PT-2019-9459 · Nimble · Nimble Messaging Bulk Sms Marketing Application
Publicado
2019-06-19
·
Atualizado
2019-06-21
·
CVE-2018-17387
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nimble Messaging Bulk SMS Marketing Application version 1.0
Description
The issue concerns a CSRF problem that allows for the addition of an admin account.
Recommendations
For Nimble Messaging Bulk SMS Marketing Application version 1.0, consider temporarily restricting access to the admin account addition functionality until a patch is available.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nimble Messaging Bulk Sms Marketing Application