What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7.
Explanation of Vulnerability in Simple Terms
MihanPanel versions before 12.7 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in administrator, performs unwanted actions on the panel without their knowledge. The attack requires the victim to visit the attacker's page while authenticated. Integrity and availability of the panel may be compromised.
What an attacker can do
Perform unwanted actions on MihanPanel (modify settings, create accounts) by tricking an authenticated admin into visiting a malicious webpage.
Potential impact on your site
An attacker can modify panel settings or data if they trick an admin into clicking a malicious link while logged in.
Conditions required to exploit
Victim must be logged into MihanPanel and visit attacker-controlled webpage; no special privileges required.
Key dates
External resources
Related vulnerabilities