Back to search
CVE-2020-11682
Published: Jun 4, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request will succeed.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20200605 Castel NextGen DVR multiple CVEs
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now