What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in SpeakPipe SpeakPipe speakpipe-voicemail-for-websites allows Cross Site Request Forgery.This issue affects SpeakPipe: from n/a through <= 0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in SpeakPipe SpeakPipe speakpipe-voicemail-for-websites allows Cross Site Request Forgery.This issue affects SpeakPipe: from n/a through <= 0.2.
Explanation of Vulnerability in Simple Terms
SpeakPipe versions 0.2 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in SpeakPipe user, performs unwanted actions on their account without their knowledge. The attack requires the victim to visit the attacker's page while authenticated to SpeakPipe. This can result in unauthorized modifications or service disruption.
What an attacker can do
Perform unwanted actions on a user's SpeakPipe account by tricking them into visiting a malicious webpage.
Potential impact on your site
Users' SpeakPipe accounts can be modified or disrupted without their consent if they visit untrusted links while logged in.
Conditions required to exploit
Victim must be logged into SpeakPipe and click a link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities