PT-2018-13647 · Monstra · Monstra Cms

Dhananjay-Bajaj

·

Publicado

2018-09-10

·

Atualizado

2019-10-03

·

CVE-2018-16608

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Monstra CMS version 3.0.4
Description The issue allows an attacker with 'Editor' privileges to change the administrator's password due to an Insecure Direct Object Reference (IDOR) vulnerability. This can be achieved by accessing the admin/index.php?id=users&action=edit&user id=1 endpoint, where the user id variable is used to specify the target user.
Recommendations For Monstra CMS version 3.0.4, restrict access to the admin/index.php endpoint for users with 'Editor' privileges until a patch is available, and consider implementing additional authentication checks to prevent unauthorized password changes.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16608

Produtos afetados

Monstra Cms