Vulnerability Description
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The application fails to validate the CSRF token for a POST request using admin privilege.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Web-School | Enterprise Resource Planning | 5.0 |
Related Weaknesses (CWE)
References
- http://web-school.inProduct
- https://github.com/0xrayan/CVEs/issues/2ExploitIssue TrackingThird Party Advisory
- https://web-school.in/try-demo/Product
- http://web-school.inProduct
- https://github.com/0xrayan/CVEs/issues/2ExploitIssue TrackingThird Party Advisory
- https://web-school.in/try-demo/Product
FAQ
What is CVE-2021-30114?
CVE-2021-30114 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The applicat...
How severe is CVE-2021-30114?
CVE-2021-30114 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-30114?
Check the references section above for vendor advisories and patch information. Affected products include: Web-School Enterprise Resource Planning.