HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-27792
发布日期2025-03-11T21:49:51.188Z
更新日期2025-03-12T13:52:10.401Z
状态PUBLISHED
受影响的供应商obiba
受影响的产品opal
描述Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns 403. However, the referrer header can be dropped from CSRF requests using ``, effectively bypassing this protection. Version 5.1.1 contains a patch for the issue.

参考链接:

Image Additional Image