CyberRota Analysis
AI-GeneratedA Cross-Site Request Forgery (CSRF) vulnerability exists in the web-based configuration backend of KUNBUS PiCtory version 2.16.0, allowing remote unauthenticated attackers to execute state-changing operations as an authenticated user. This could lead to the deletion of project files and configuration settings, as well as the reset of the control runtime. Organizations using this version should prioritize remediation to mitigate potential unauthorized access and data loss.
Original NVD Description
Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an authenticated operator, including deletion of project and configuration files and reset of the control runtime, by inducing the victim's browser to submit crafted requests.