PT-2018-12489 · Creme · Creme Crm

Publicado

2018-09-07

·

Atualizado

2018-11-14

·

CVE-2018-14398

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Creme CRM version 1.6.12
Description An issue was discovered where the value of the cancel button uses the content of the HTTP Referer header. This could be used to trick a user into visiting a fake login page in order to steal credentials.
Recommendations For Creme CRM version 1.6.12, consider disabling the cancel button functionality until a patch is available to prevent potential credential theft.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14398

Produtos afetados

Creme Crm