BeyondTrust Secure Remote Access Base Software through 6...
Critical severity
Unreviewed
Published
Feb 8, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 5, 2022
Published to the GitHub Advisory Database
Feb 8, 2022
Last updated
Feb 3, 2023
BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server
References