Security Advisory

CVE-2017-7926

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-08-25 19:00:00
Last updated 2024-08-05 16:19:29
Assigner icscert
CVSS score not scored
State PUBLISHED

Description

A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur when an otherwise-unauthorized cross-site request is sent from a browser the server has previously authenticated.