BeyondTrust Secure Remote Access Base Software through 6...
        
  Critical severity
        
          Unreviewed
      
        Published
          Feb 8, 2022 
          to the GitHub Advisory Database
          •
          Updated Feb 3, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Jan 5, 2022 
    
  
        Published to the GitHub Advisory Database
      Feb 8, 2022 
    
  
        Last updated
      Feb 3, 2023 
    
  
BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint. This cross-site-scripting (XSS) vulnerability occurs when it does not properly sanitize an unauthenticated crafted web request to the server
References