Description
OrientDB 3.0.17 GA Community Edition contains cross-site request forgery vulnerabilities that allow attackers to perform unauthorized actions by crafting malicious requests to endpoints like /database/, /command/, and /document/. Attackers can create or delete databases, modify schema classes, manage users, and create functions by sending authenticated requests without token validation, combined with reflected and stored cross-site scripting vulnerabilities in the web interface.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Ozer Goker
References
www.exploit-db.com/exploits/46517 (ExploitDB-46517)
orientdb.dev/ (OrientDB Official Website)
www.vulncheck.com/...ies/orientdb-cross-site-request-forgery (VulnCheck Advisory: OrientDB 3.0.17 Cross-Site Request Forgery)