Description
Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
1.0 (firmware)
Timeline
| 2024-06-27: | Reported |
Credits
Armando Huesca Prida
Marco Negro
Antonio Carriero
Vito Pistillo
Davide Renna
Manuel Leone
Massimiliano Brolli
TIM Security Red Team Research
References
www.gruppotim.it/it/footer/red-team.html
www.microchip.com/...-grandmaster-cross-site-request-forgery