A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF attack.
- https://github.com/DRAGOWN/CVE-2024-56901
- https://github.com/DRAGOWN/CVE-2024-56898
- https://github.com/DRAGOWN/CVE-2024-56901
- https://github.com/DRAGOWN/CVE-2024-56902
- https://github.com/DRAGOWN/CVE-2024-56903
- https://github.com/plzheheplztrying/cve_monitor