PT-2017-6770 · Spina · Spina

Publicado

2017-09-07

·

Atualizado

2018-08-28

·

CVE-2015-4619

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spina versions prior to commit bfe44f289e336f80b6593032679300c493735e75
Description The issue is a cross-site request forgery (CSRF) vulnerability. It affects the Spina::ApplicationController actions, which lacked CSRF protection. This results in a CSRF vulnerability across the entire engine, including administrative functionality such as creating users, changing passwords, and media management.
Recommendations For versions prior to commit bfe44f289e336f80b6593032679300c493735e75, update to a version that includes the fix for this issue. As a temporary workaround, consider implementing CSRF protection for Spina::ApplicationController actions to minimize the risk of exploitation. Restrict access to administrative functionality, such as creating users, changing passwords, and media management, until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-4619
GHSA-2HXV-MX8X-MCJ9

Produtos afetados

Spina