Back

MEDIUM

Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator

Published Apr 5, 2023

Description

Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Apr 5, 2023
Updated Feb 13, 2025
Reserved Feb 22, 2023
CISA Vulnrichment
Updated Feb 13, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Fluid Attacks
Published Apr 5, 2023
Updated Feb 13, 2025
Exploited since n/a
EUVD-2023-12944