PT-2017-12104 · Cesanta · Mongoose Web Server

Hyp3Rlinx

+1

·

Published

2017-09-07

·

Updated

2017-09-18

·

CVE-2017-11567

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mongoose Web Server versions prior to 6.9
Description A cross-site request forgery (CSRF) issue allows remote attackers to hijack user authentication for requests that modify Mongoose.conf via a request to " mg admin?save". This can be leveraged to execute arbitrary code remotely.
Recommendations For versions prior to 6.9, update to version 6.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the mg admin?save request to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11567

Affected Products

Mongoose Web Server