Vulnerabilities > Rainworx > Auctionworx > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-05-02 CVE-2022-23904 Cross-Site Request Forgery (CSRF) vulnerability in Rainworx Auctionworx
Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel.
network
rainworx CWE-352
6.0