PT-2026-67341 · Unknown · Cti-Transmute
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
CTI-Transmute (affected versions not specified)
Description
A cross-site request forgery issue exists in the administrative user deletion functionality. The '/account/delete/' endpoint accepted HTTP GET requests for operations that modified application state. An unauthenticated remote attacker could induce an authenticated administrator with an active session to visit a malicious link, causing the browser to automatically include session credentials and delete a selected user account without confirmation. This could lead to the unauthorized deletion of arbitrary user accounts, resulting in denial of access for users or disruption of the instance administration. The exploitation relies on the
id variable to specify the target account.Recommendations
Restrict the '/account/delete/' endpoint to HTTP POST requests and implement a CSRF token within the deletion form.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cti-Transmute