PT-2010-3724 · Brekeke · Brekeke Pbx
John Leitch
·
Published
2010-05-28
·
Updated
2010-06-01
·
CVE-2010-2114
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Brekeke PBX version 2.4.4.8
Description
A cross-site request forgery (CSRF) issue allows remote attackers to hijack user authentication for requests that change passwords via the pbxadmin.web.PbxUserEdit bean.
Recommendations
For Brekeke PBX version 2.4.4.8, consider disabling the pbxadmin.web.PbxUserEdit bean as a temporary workaround until a patch is available. Restrict access to the password change functionality to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brekeke Pbx