PT-2018-9261 · Ajenti · Ajenti
Published
2018-03-13
·
Updated
2018-04-06
·
CVE-2018-1000082
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Ajenti version 2
Description:
The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. This can result in code execution on the server. The attack is exploitable via a CSRF, which requires victim interaction. When the victim accesses the infected trigger of the CSRF, any code that matches the victim's privileges on the server can be executed.
Recommendations:
For Ajenti version 2, consider disabling the command execution panel until a patch is available to prevent potential code execution on the server. Restrict access to the server management tool to minimize the risk of exploitation. Avoid using the tool for critical operations until the issue is resolved.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ajenti