Description
An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-5457 | An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link. |
References
| Link | Providers |
|---|---|
| https://advisory.teradici.com/security-advisories/70/ |
|
History
No history.
Status: PUBLISHED
Assigner: Teradici
Published:
Updated: 2024-08-04T12:11:19.410Z
Reserved: 2020-05-19T00:00:00.000Z
Link: CVE-2020-13186
No data.
Status : Modified
Published: 2021-02-11T18:15:14.127
Modified: 2024-11-21T05:00:49.280
Link: CVE-2020-13186
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD