Loading
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.
Use CWE-352, Ui vendor hub and Unifi Video product page to widen CVE-2019-5430 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-8144, CVE-2020-24755 and CVE-2020-8146 for nearby disclosures in the same product family.