CVE-2021-34244

HIGH

Icehrm - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change users' passwords.

Scores

CVSS v3 8.8
EPSS 0.0057
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
icehrm/icehrm 29.0.0.os
Published Jun 22, 2021
Tracked Since Feb 18, 2026