PT-2018-19078 · Kotti · Kotti

Ehaoxiongdiycwo

·

Publicado

2018-04-09

·

Atualizado

2018-07-12

·

CVE-2018-9856

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kotti versions prior to 1.3.2 Kotti versions 2.x prior to 2.0.0b2
Description The issue concerns a CSRF problem in the local roles implementation. It can be triggered by a permission change via the "/admin-document/@@share" API endpoint.
Recommendations For versions prior to 1.3.2, update to version 1.3.2 or later. For versions 2.x prior to 2.0.0b2, update to version 2.0.0b2 or later.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-9856
GHSA-3HQ4-F2V6-Q338
PYSEC-2018-10

Produtos afetados

Kotti