Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Usermuzilio

#15223de 53,638
17.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2018-12941
8.8
2018-08-08
Onethink · Onethink · CVE-2018-15197
**Name of the Vulnerable Software and Affected Versions** OneThink version 1.1 **Description** A CSRF issue was found in the admin.php?s=/AuthManager/addToGroup.html endpoint, allowing for the potential granting of administrator privileges. **Recommendations** For OneThink version 1.1, as a temporary workaround, consider restricting access to the `admin.php?s=/AuthManager/addToGroup.html` endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
PT-2018-12942
8.8
2018-08-08
Onethink · Onethink · CVE-2018-15198
**Name of the Vulnerable Software and Affected Versions** OneThink version 1.1 **Description** An issue was discovered that allows for a CSRF vulnerability. The vulnerability can be exploited through the "admin.php?s=/User/add.html" endpoint, which can add a user. **Recommendations** For OneThink version 1.1, consider implementing CSRF protection measures to prevent unauthorized actions, such as adding a user through the "admin.php?s=/User/add.html" endpoint. As a temporary workaround, restrict access to this endpoint to minimize the risk of exploitation.