Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/s3131212/allendisk/issues/16 | Issue Tracking Patch Third Party Advisory | 
| https://github.com/s3131212/allendisk/issues/16 | Issue Tracking Patch Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 03:34
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/s3131212/allendisk/issues/16 - Issue Tracking, Patch, Third Party Advisory | 
Information
                Published : 2017-05-08 17:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-8848
Mitre link : CVE-2017-8848
CVE.ORG link : CVE-2017-8848
JSON object : View
Products Affected
                allen_disk_project
- allen_disk
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
