CVE-2023-7273

MEDIUM

Kiteworks OwnCloud < 10.12.2 - Cross-Site Request Forgery via Authorization Header Bypass

Title source: llm
STIX 2.1

Description

Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with an empty string as value by a rewrite rule. The CSRF check is done by comparing the header value to null, meaning that the existing CSRF check is bypassed in this case. An attacker can, for example, create a new administrator account if the request is executed in the browser of an authenticated victim.

References (2)

Core 2
Core References
Third Party Advisory issue-tracking
https://hackerone.com/reports/2041007
Various Sources third-party-advisory
https://cirosec.de/sa/sa-2023-012

Scores

CVSS v3 6.8
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (1)
Kiteworks/OwnCloud < 10.12.2
Published Oct 01, 2024
Tracked Since Feb 18, 2026