PT-2018-9261 · Ajenti · Ajenti

Publicado

2018-03-13

·

Atualizado

2018-04-06

·

CVE-2018-1000082

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ajenti version 2
Description: The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. This can result in code execution on the server. The attack is exploitable via a CSRF, which requires victim interaction. When the victim accesses the infected trigger of the CSRF, any code that matches the victim's privileges on the server can be executed.
Recommendations: For Ajenti version 2, consider disabling the command execution panel until a patch is available to prevent potential code execution on the server. Restrict access to the server management tool to minimize the risk of exploitation. Avoid using the tool for critical operations until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000082
PYSEC-2018-111

Produtos afetados

Ajenti