Vulnerability Description
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Icehrm | Icehrm | 31.0.0.os |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/166627/ICEHRM-31.0.0.0S-Cross-Site-Request-ExploitThird Party AdvisoryVDB Entry
- https://medium.com/%40devansh3008/csrf-in-icehrm-31-0-0-0s-in-delete-user-endpoi
- http://packetstormsecurity.com/files/166627/ICEHRM-31.0.0.0S-Cross-Site-Request-ExploitThird Party AdvisoryVDB Entry
- https://medium.com/%40devansh3008/csrf-in-icehrm-31-0-0-0s-in-delete-user-endpoi
FAQ
What is CVE-2022-26588?
CVE-2022-26588 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
How severe is CVE-2022-26588?
CVE-2022-26588 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26588?
Check the references section above for vendor advisories and patch information. Affected products include: Icehrm Icehrm.