CVE-2022-41413
MEDIUMperfSONAR 4.0-4.4.5 - Cross-Site Request Forgery via Search Function
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-41413. PoCs published by Ryan Moore, renmizo.
AI-analyzed exploit summary The exploit describes a partial blind CSRF vulnerability in perfSONAR v4.x <= v4.4.5, where URL parameters can be manipulated to force the client to make unintended XMLHTTPRequests to arbitrary sites or endpoints. The vulnerability bypasses built-in whitelisting functions.
Description
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.
Exploits (2)
The exploit describes a partial blind CSRF vulnerability in perfSONAR v4.x <= v4.4.5, where URL parameters can be manipulated to force the client to make unintended XMLHTTPRequests to arbitrary sites or endpoints. The vulnerability bypasses built-in whitelisting functions.
This repository documents a partial blind CSRF vulnerability in perfSONAR v4.x <= v4.4.5, where URL parameters can bypass whitelisting to force background XMLHTTPRequests to arbitrary sites. The PoC demonstrates parameter injection via the 'dest' field to execute unauthenticated CSRF attacks.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N