VYPR
High severity8.8NVD Advisory· Published Jul 24, 2023· Updated Jun 17, 2026

CVE-2022-30280

CVE-2022-30280

Description

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nokia/NetAct2 versions
    cpe:2.3:a:nokia:netact:22.0.0.62:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nokia:netact:22.0.0.62:*:*:*:*:*:*:*
    • (no CPE)
  • Nokia/NetActdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.