PT-2019-13562 · Publisure · Publisure

Bourbon Jean-Marie

+1

·

Published

2019-09-18

·

Updated

2020-08-24

·

CVE-2019-14253

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Publisure version 2.1.2
Description An issue in the servlet controller of the secure portal allows authentication bypass, enabling unauthorized queries on PHP forms within the /AdminDir folder, which should be restricted.
Recommendations For Publisure version 2.1.2, consider restricting access to the /AdminDir folder and its PHP forms until a patch is available. As a temporary workaround, review and strengthen authentication mechanisms to prevent bypass attempts.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14253

Affected Products

Publisure