PT-2010-3724 · Brekeke · Brekeke Pbx
John Leitch
·
Publicado
2010-05-28
·
Atualizado
2010-06-01
·
CVE-2010-2114
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Brekeke PBX version 2.4.4.8
Description
A cross-site request forgery (CSRF) issue allows remote attackers to hijack user authentication for requests that change passwords via the pbxadmin.web.PbxUserEdit bean.
Recommendations
For Brekeke PBX version 2.4.4.8, consider disabling the pbxadmin.web.PbxUserEdit bean as a temporary workaround until a patch is available. Restrict access to the password change functionality to minimize the risk of exploitation.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Brekeke Pbx