CVE编号 | CVE-2025-27792 |
---|---|
发布日期 | 2025-03-11T21:49:51.188Z |
更新日期 | 2025-03-12T13:52:10.401Z |
状态 | PUBLISHED |
受影响的供应商 | obiba |
受影响的产品 | opal |
描述 | Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns 403. However, the referrer header can be dropped from CSRF requests using ``, effectively bypassing this protection. Version 5.1.1 contains a patch for the issue. |
参考链接: