PT-2019-13626 · Unknown · Schben Adive
Pablo Santiago
·
Publicado
2019-08-06
·
Atualizado
2023-03-03
·
CVE-2019-14347
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Schben Adive version 2.0.7
Description
The issue allows remote unprivileged users, such as editors or developers, to create an administrator account. This can be achieved via the
admin/user/add endpoint, as demonstrated by a Python proof-of-concept script.Recommendations
For Schben Adive version 2.0.7, consider restricting access to the
admin/user/add endpoint until a patch is available. As a temporary workaround, limit the ability of unprivileged users to create new administrator accounts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Schben Adive