CVE-2023-33409
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2023-33409 refers to a Cross-Site Request Forgery (CSRF) vulnerability affecting Minical 1.0.0. This issue enables an attacker to potentially manipulate a victim's web session by tricking them into making unintended actions on the website. Specifically, the vulnerability resides in minical/public/application/controllers/settings/company.php, which could lead to undesired changes in the company settings if an adversary successfully executes a CSRF attack. This vulnerability poses a serious risk, and users are advised to update their Minical installation to a patched version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.