PT-2018-12489 · Creme · Creme Crm

Published

2018-09-07

·

Updated

2018-11-14

·

CVE-2018-14398

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Creme CRM version 1.6.12
Description An issue was discovered where the value of the cancel button uses the content of the HTTP Referer header. This could be used to trick a user into visiting a fake login page in order to steal credentials.
Recommendations For Creme CRM version 1.6.12, consider disabling the cancel button functionality until a patch is available to prevent potential credential theft.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14398

Affected Products

Creme Crm