•  
      request #42231 Missing CSRF protection on tracker hierarchy administration
    Infos
    #42231
    Joris MASSON (jmasson)
    2025-03-31 10:16
    2025-03-17 19:13
    43907
    Details
    Missing CSRF protection on tracker hierarchy administration

    In the administration of a Tracker, in the "Tracker hierarchy", there is no CSRF protection when choosing the list of children trackers.

    Impact

    An attacker could use this vulnerability to trick victims into changing the hierarchy of a tracker.

    CVSSv3.1 score: 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)

    References

    CWE 352
    Cross-Site Request Forgery - OWASP
    CVE-2025-29929

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2025-03-18
    Attachments
    Empty
    References

    Follow-ups

    User avatar

    CVE-2025-29929 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    close
    by