CVE-2019-7281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
01/07/2019
Last modified:
25/10/2022

Description

Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:* 2.3.38 (including)