Back to search
CVE-2021-47702
Published: Dec 9, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by exploiting the sendFeedback.php endpoint. Attackers can submit malicious requests to trigger unintended actions, such as sending emails or modifying system settings.
| Vendor | Product | Versions |
|---|---|---|
OPEN BMCS | OpenBMCS | affected 2.4 |
Weaknesses (CWE)
References
ExploitDB-50667
exploit
Official Product Homepage
product
Zero Science Lab Disclosure (ZSL-2022-5691)
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now