CyberRota Analysis
AI-GeneratedThe Sustainable Irrigation Platform (SIP) versions up to 5.2.16 are vulnerable to a mass assignment flaw that enables unauthenticated attackers to overwrite critical configuration settings via arbitrary HTTP parameters. This vulnerability can lead to unauthorized access to sensitive values, including passphrases and listening ports, and is further exacerbated by insufficient request validation, allowing for cross-site request forgery attacks. Organizations using this platform should prioritize remediation to mitigate the risk of unauthorized configuration changes and potential system compromise.
Original NVD Description
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)