An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24982
Reference (s):
- https://c41nc.co.uk/cve-2020-24982/

