PT-2018-18757 · Open Audit · Open-Audit Professional

Nilesh Sapariya

+1

·

Published

2018-03-25

·

Updated

2020-08-24

·

CVE-2018-8979

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open-AudIT Professional version 2.1
Description The issue allows for Cross-Site Request Forgery (CSRF) attacks, which can be used to modify user accounts or inject XSS sequences. This can be achieved by manipulating the credentials URI.
Recommendations For Open-AudIT Professional version 2.1, consider implementing CSRF protection mechanisms to prevent unauthorized modifications to user accounts and injection of XSS sequences. As a temporary workaround, restrict access to the credentials URI to minimize the risk of exploitation.

Exploit

Fix

CSRF

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8979

Affected Products

Open-Audit Professional