PT-2018-10619 · Mybb · Moderator Log Notes Plugin

0Xb9

·

Publicado

2018-08-24

·

Atualizado

2018-10-31

·

CVE-2018-11502

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moderator Log Notes plugin version 1.1 for MyBB
Description The issue allows an attacker to remotely delete all moderator notes and logs in the moderator control panel (modCP) and administrator control panel (ACP) via a Cross-Site Request Forgery (CSRF) attack. This enables unauthorized modification of sensitive data.
Recommendations For Moderator Log Notes plugin version 1.1, consider implementing CSRF protection mechanisms to prevent unauthorized requests. As a temporary workaround, restrict access to the modCP and ACP to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11502

Produtos afetados

Moderator Log Notes Plugin