Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled page, allowing the attacker to gain admin privileges in the system.
2018-03-22T14:29:00.287
2024-11-21T03:03:55.573
Modified
CVSSv3.0: 8.0 (HIGH)
AV:N/AC:M/Au:S/C:C/I:C/A:C
6.8
10.0