An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect authentication is in use and a user visits a compromised/malicious site, or (2) when username/password or Active Directory authentication is in use and a user visits a compromised/malicious site under the same effective top-level domain as the Seq server. Exploitation of the vulnerability allows the attacker to conduct impersonation attacks and perform actions in Seq on behalf of the targeted user.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect authentication is in use and a user visits a compromised/malicious site, or (2) when username/password or Active Directory authentication is in use and a user visits a compromised/malicious site under the same effective top-level domain as the Seq server. Exploitation of the vulnerability allows the attacker to conduct impersonation attacks and perform actions in Seq on behalf of the targeted user. | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-11T00:00:00.000Z
Updated: 2025-03-11T13:20:54.633Z
Reserved: 2025-03-10T00:00:00.000Z
Link: CVE-2025-27912

Updated: 2025-03-11T13:20:47.977Z

Status : Received
Published: 2025-03-11T08:15:11.727
Modified: 2025-03-11T08:15:11.727
Link: CVE-2025-27912

No data.