VulnerabilityModified
CVE-2020-21989
HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF).
HIGH 8.8EPSS 0.75%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- homeautomation project/homeautomation
- Source
- cve@mitre.org
References
- https://www.exploit-db.com/exploits/47808Exploit, Third Party Advisory, VDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5558.phpExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/47808Exploit, Third Party Advisory, VDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5558.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.