A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magewell ultra Encode Aio
Magewell ultra Encode Aio Firmware Magewell ultra Encode Hdmi Magewell ultra Encode Hdmi Firmware Magewell ultra Encode Hdmi Plus Magewell ultra Encode Hdmi Plus Firmware Magewell ultra Encode Sdi Magewell ultra Encode Sdi Firmware Magewell ultra Encode Sdi Plus Magewell ultra Encode Sdi Plus Firmware |
|
| CPEs | cpe:2.3:h:magewell:ultra_encode_aio:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_hdmi:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_hdmi_plus:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_sdi:-:*:*:*:*:*:*:* cpe:2.3:h:magewell:ultra_encode_sdi_plus:-:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_aio_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_hdmi_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_hdmi_plus_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_sdi_firmware:2.3.206:*:*:*:*:*:*:* cpe:2.3:o:magewell:ultra_encode_sdi_plus_firmware:2.3.206:*:*:*:*:*:*:* |
|
| Vendors & Products |
Magewell ultra Encode Aio
Magewell ultra Encode Aio Firmware Magewell ultra Encode Hdmi Magewell ultra Encode Hdmi Firmware Magewell ultra Encode Hdmi Plus Magewell ultra Encode Hdmi Plus Firmware Magewell ultra Encode Sdi Magewell ultra Encode Sdi Firmware Magewell ultra Encode Sdi Plus Magewell ultra Encode Sdi Plus Firmware |
Wed, 26 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magewell
Magewell convert |
|
| Vendors & Products |
Magewell
Magewell convert |
Mon, 24 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-24T19:03:16.840Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63953
Updated: 2025-11-24T19:02:36.328Z
Status : Analyzed
Published: 2025-11-24T17:16:08.760
Modified: 2025-12-30T17:58:54.510
Link: CVE-2025-63953
No data.
OpenCVE Enrichment
Updated: 2025-11-26T11:10:44Z