PT-2023-10833 · Unknown · Mdalamin-Aol Own Health Record

Mdalamin-Aol

·

Publicado

2023-12-30

·

Atualizado

2024-05-17

·

CVE-2018-25096

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MdAlAmin-aol Own Health Record versions 0.1-alpha through 0.3.1-alpha
Description This issue affects some unknown processing of the file includes/logout.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely.
Recommendations For MdAlAmin-aol Own Health Record versions 0.1-alpha through 0.3.1-alpha, upgrade to version 0.4-alpha to address this issue. As a temporary workaround, consider restricting access to the includes/logout.php file until the upgrade is applied.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-25096

Produtos afetados

Mdalamin-Aol Own Health Record