PT-2019-15554 · 3Xlogic · 3Xlogic Infinias Access Control
Published
2019-11-14
·
Updated
2019-11-20
·
CVE-2019-18651
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
3xLogic Infinias Access Control versions prior to 6.6.9586.0
Description
A cross-site request forgery issue allows remote attackers to execute malicious actions by sending a crafted HTML document or encoded URL to a user with an active privileged session, potentially leading to unauthorized actions such as deleting application users.
Recommendations
For versions prior to 6.6.9586.0, update to a version that includes the fix for this issue to prevent remote attackers from executing malicious actions. As a temporary workaround, consider restricting access to privileged sessions and validating user requests to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
3Xlogic Infinias Access Control