CVE-2019-13071

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
10/07/2019
Last modified:
09/10/2019

Description

CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyberpowersystems:powerpanel:3.4.0:*:*:*:business:*:*:*