CVE-2023-33534
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jul 31, 2023
Updated: Aug 4, 2023
CWE ID 352
Summary
CVE-2023-33534 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Guanzhou Tozed Kangwei Intelligent Technology's ZLTS10G software version S10G_3.11.6. This issue enables attackers to take over user accounts by sending carefully crafted POST requests to the /goform/goform_set_cmd_process endpoint. The CSRF exploit manipulates unsuspecting users to execute unintended commands, putting their accounts at risk. This vulnerability underscores the importance of implementing robust CSRF protection mechanisms to secure web applications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share