Sismics Teedy
cpe:2.3:a:sismics:teedy:*:*:*:*:*:*:*
- <= 1.11
A cross-site request forgery (CSRF) vulnerability has been identified in Teedy versions through 1.11. This vulnerability allows for account takeover by sending a POST request to the /api/user/admin endpoint.
Exploitation of this vulnerability could lead to unauthorized account access and administrative privileges on the affected Teedy instance.
To reproduce this vulnerability, send a POST request to the /api/user/admin endpoint from a user account that is not an administrator. The request must include the necessary CSRF token to bypass protection mechanisms. If successful, the account will be granted administrative privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.