Overview
First Published: November 24, 2021Version: 1.0
Revision: 1.0
Summary
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.
This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.
Affected Products:
All UniFi OS Consoles hosting the UniFi Protect application
Mitigation:
Update the UniFi Protect application to Version 1.20.0 or later.
Impact:
CVSS v3.0 Severity and Metrics:
Base Score: 7.5 High
Vector:
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference Links:
https://community.ui.com/releases/U...n-1-20-0/d43c0905-3fb4-456b-a7ca-73aa830cb011