Vulnerabilities > Rainworx

DATE CVE VULNERABILITY TITLE RISK
2022-05-02 CVE-2022-23904 Cross-Site Request Forgery (CSRF) vulnerability in Rainworx Auctionworx 3.1
Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel.
network
low complexity
rainworx CWE-352
8.0