CVE-2023-7273

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 352

Summary

CVE-2023-7273 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Kiteworks OwnCloud. An attacker can exploit this issue by forging requests that bypass the CSRF check. If a request has no Authorization header, it is assigned an empty string value by a rewrite rule, enabling the attacker to bypass the CSRF protection. This vulnerability could potentially allow an unauthenticated attacker to create new administrator accounts if the malicious request is executed in the browser of an authenticated victim.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share