What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in TMS Amelia.This issue affects Amelia: from n/a through 1.0.95.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in TMS Amelia.This issue affects Amelia: from n/a through 1.0.95.
Explanation of Vulnerability in Simple Terms
Amelia versions up to 1.0.95 contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unwanted actions on behalf of a logged-in user. The vulnerability requires user interaction—typically clicking a malicious link or visiting a compromised page. An attacker can modify data or trigger actions within Amelia, but cannot read sensitive information.
What an attacker can do
Perform unwanted actions on behalf of a logged-in user, such as modifying bookings or settings.
Potential impact on your site
Users' Amelia data (bookings, appointments, settings) can be altered without their knowledge if they visit untrusted sites while logged in.
Conditions required to exploit
A logged-in user must visit an attacker-controlled page or click a malicious link while authenticated to Amelia.
Key dates
External resources
Related vulnerabilities