Security Advisory

CVE-2021-37366

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-08-10 15:12:41
Last updated 2024-08-04 01:16:04
Assigner mitre
State PUBLISHED

Description

CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.