CVE-2019-5430

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
06/05/2019
Last modified:
09/10/2019

Description

In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ui:unifi_video:*:*:*:*:*:*:*:* 3.10.0 (including)