What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Latepoint LatePoint allows Cross Site Request Forgery.This issue affects LatePoint: from n/a through 4.9.91.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Latepoint LatePoint allows Cross Site Request Forgery.This issue affects LatePoint: from n/a through 4.9.91.
Explanation of Vulnerability in Simple Terms
LatePoint versions up to 4.9.91 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in LatePoint user, performs unwanted actions on their behalf without their knowledge. The vulnerability requires user interaction—the victim must visit the attacker's page while authenticated. No authentication is required from the attacker's side.
What an attacker can do
Perform actions on a LatePoint user's account without their consent by tricking them into visiting a malicious webpage.
Potential impact on your site
Users' LatePoint accounts can be manipulated to perform unintended actions (e.g., booking changes, data modification) if they click malicious links.
Conditions required to exploit
Victim must be logged into LatePoint and visit attacker-controlled webpage; attacker needs no authentication.
Key dates
External resources
Related vulnerabilities