CVE-2021-31584

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
23/04/2021
Last modified:
30/07/2022

Description

Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sipwise:next_generation_communication_platform:3.6.4:*:*:*:ce:*:*:*