CVE-2021-28055

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
15/04/2021
Last modified:
28/06/2022

Description

An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:centreon:centreon:20.10.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools