PT-2019-14689 · Layerbb · Layerbb
0Xb9
·
Publicado
2019-09-20
·
Atualizado
2019-09-20
·
CVE-2019-16531
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LayerBB versions prior to 1.1.4
Description
The issue allows for multiple CSRF problems, which can be demonstrated by modifying the System Settings through the "admin/general.php" endpoint, specifically by exploiting the lack of proper CSRF protection.
Recommendations
For versions prior to 1.1.4, update to version 1.1.4 or later to resolve the issue. As a temporary workaround, consider implementing additional CSRF protection measures for the "admin/general.php" endpoint until the update can be applied.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Layerbb