PT-2018-19078 · Kotti · Kotti

Ehaoxiongdiycwo

·

Published

2018-04-09

·

Updated

2018-07-12

·

CVE-2018-9856

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kotti versions prior to 1.3.2 Kotti versions 2.x prior to 2.0.0b2
Description The issue concerns a CSRF problem in the local roles implementation. It can be triggered by a permission change via the "/admin-document/@@share" API endpoint.
Recommendations For versions prior to 1.3.2, update to version 1.3.2 or later. For versions 2.x prior to 2.0.0b2, update to version 2.0.0b2 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9856
GHSA-3HQ4-F2V6-Q338
PYSEC-2018-10

Affected Products

Kotti