dataCycle-CORE
- <= 25.07.3
A vulnerability in dataCycle-CORE versions prior to 25.07.3 allows for server-side request forgery (SSRF) by exploiting state-changing GET endpoints. The application fails to apply proper Cross-Site Request Forgery (CSRF) protections to GET requests, enabling attackers to manipulate application state on behalf of logged-in users. This can be achieved by embedding a link or redirecting to a vulnerable endpoint, such as 'watch_lists/:id/add_item?thing_id=...', which adds items to a watch list without requiring a CSRF token. Other GET mutation routes are also available, including user impersonation for authorized admins and changes to cache or translation states.
Exploitation of this vulnerability allows for unauthorized modification of application state, including adding items to watch lists and impersonating users with admin privileges.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.