PT-2019-13626 · Unknown · Schben Adive
Pablo Santiago
·
Published
2019-08-06
·
Updated
2023-03-03
·
CVE-2019-14347
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Schben Adive version 2.0.7
Description
The issue allows remote unprivileged users, such as editors or developers, to create an administrator account. This can be achieved via the
admin/user/add endpoint, as demonstrated by a Python proof-of-concept script.Recommendations
For Schben Adive version 2.0.7, consider restricting access to the
admin/user/add endpoint until a patch is available. As a temporary workaround, limit the ability of unprivileged users to create new administrator accounts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Schben Adive