CVE-2019-25447
EUVD-2019-1960620.02.2026, 23:16
OrientDB 3.0.17 GA Community Edition contains cross-site request forgery vulnerabilities that allow attackers to perform unauthorized actions by crafting malicious requests to endpoints like /database/, /command/, and /document/. Attackers can create or delete databases, modify schema classes, manage users, and create functions by sending authenticated requests without token validation, combined with reflected and stored cross-site scripting vulnerabilities in the web interface.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| orientdb | orientdb | 3.0.17 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration