PT-2017-6770 · Spina · Spina
Published
2017-09-07
·
Updated
2018-08-28
·
CVE-2015-4619
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spina versions prior to commit bfe44f289e336f80b6593032679300c493735e75
Description
The issue is a cross-site request forgery (CSRF) vulnerability. It affects the
Spina::ApplicationController actions, which lacked CSRF protection. This results in a CSRF vulnerability across the entire engine, including administrative functionality such as creating users, changing passwords, and media management.Recommendations
For versions prior to commit bfe44f289e336f80b6593032679300c493735e75, update to a version that includes the fix for this issue. As a temporary workaround, consider implementing CSRF protection for
Spina::ApplicationController actions to minimize the risk of exploitation. Restrict access to administrative functionality, such as creating users, changing passwords, and media management, until the issue is resolved.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spina