/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker’s choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.
More Stories
python-jinja2-3.1.5-1.fc40
FEDORA-2025-6ed1e0c3c6 Packages in this update: python-jinja2-3.1.5-1.fc40 Update description: Update to 3.1.5 Security fix for CVE-2024-56201 Read More
python-jinja2-3.1.5-1.fc41
FEDORA-2025-7b6e208ef2 Packages in this update: python-jinja2-3.1.5-1.fc41 Update description: Update to 3.1.5 Security fix for CVE-2024-56201 Read More
chromium-131.0.6778.264-1.el9
FEDORA-EPEL-2025-56fc9b1754 Packages in this update: chromium-131.0.6778.264-1.el9 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More
chromium-131.0.6778.264-1.fc41
FEDORA-2025-212c5c45ce Packages in this update: chromium-131.0.6778.264-1.fc41 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More
chromium-131.0.6778.264-1.el10_0
FEDORA-EPEL-2025-10c786286b Packages in this update: chromium-131.0.6778.264-1.el10_0 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More
chromium-131.0.6778.264-1.el8
FEDORA-EPEL-2025-b65cef2f93 Packages in this update: chromium-131.0.6778.264-1.el8 Update description: Update to 131.0.6778.264 * High CVE-2025-0291: Type Confusion in V8 Read More