PT-2019-9461 · Unknown · Live Call Support Application
Publicado
2019-06-19
·
Atualizado
2019-06-20
·
CVE-2018-17389
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Live Call Support Application version 1.5
Description
The issue exists in the server.php file, allowing for the addition of an admin account due to CSRF.
Recommendations
For version 1.5, update the server.php file to include proper CSRF protection mechanisms, such as token validation, to prevent unauthorized admin account additions.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Live Call Support Application