CVE detail
CVE-2023-4659 — CVE-2023-4659
Published 2023-10-02 · Modified 2026-06-17 · Vendor free5gc · Product free5gc · Source nvd
CRITICAL
severity
CVSS-derived band
0.0033
EPSS probability
exploitation probability, 30d
26.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References