PT-2019-9459 · Nimble · Nimble Messaging Bulk Sms Marketing Application

Publicado

2019-06-19

·

Atualizado

2019-06-21

·

CVE-2018-17387

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nimble Messaging Bulk SMS Marketing Application version 1.0
Description The issue concerns a CSRF problem that allows for the addition of an admin account.
Recommendations For Nimble Messaging Bulk SMS Marketing Application version 1.0, consider temporarily restricting access to the admin account addition functionality until a patch is available.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17387

Produtos afetados

Nimble Messaging Bulk Sms Marketing Application