This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
| Software | From | Fixed in |
|---|---|---|
| hcltech / bigfix_inventory | 9.0 | 10.0.7.0 |