A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS...
Moderate severity
Unreviewed
Published
Apr 9, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 8, 2022
Published to the GitHub Advisory Database
Apr 9, 2022
Last updated
Jan 27, 2023
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
References