CVE-2021-47702
MEDIUMOpenbmcs - CSRF
Title source: ruleDescription
OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by exploiting the sendFeedback.php endpoint. Attackers can submit malicious requests to trigger unintended actions, such as sending emails or modifying system settings.
Exploits (1)
References (4)
Scores
CVSS v3
4.3
EPSS
0.0005
EPSS Percentile
16.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-352
Status
published
Affected Products (1)
openbmcs/openbmcs
Timeline
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026