Critical severity9.8NVD Advisory· Published Oct 2, 2023· Updated Jun 17, 2026
CVE-2023-4659
CVE-2023-4659
Description
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Free5Gc/Open5Gcv5Range: 1.1.1
Patches
Vulnerability mechanics
References
1- www.incibe.es/en/incibe-cert/notices/aviso/cross-site-request-forgery-free5gcnvdThird Party Advisory
News mentions
0No linked articles in our index yet.