PT-2018-10303 · Mybb · Mybb Admin Notes Plugin
Publicado
2018-05-21
·
Atualizado
2018-06-25
·
CVE-2018-11092
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MyBB Admin Notes plugin version 1.1
Description
An issue allows an attacker to remotely delete all admin notes. This can be achieved via the "admin/index.php?empty=table" action, which is vulnerable to CSRF.
Recommendations
For MyBB Admin Notes plugin version 1.1, consider disabling the "empty=table" action in the admin/index.php file as a temporary workaround until a patch is available. Restrict access to the admin/index.php file to minimize the risk of exploitation.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mybb Admin Notes Plugin