CVE-2020-24984

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
11/03/2021
Last modified:
18/03/2021

Description

An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quadbase:espressreports_es:7:update_9:*:*:*:*:*:*


References to Advisories, Solutions, and Tools