PT-2019-6772 · Letodms · Letodms

Nightrang3R

·

Published

2019-11-13

·

Updated

2019-11-15

·

CVE-2012-4385

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions letodms version 3.3.6
Description The issue allows for CSRF via the change password function.
Recommendations For letodms version 3.3.6, update to a version that includes a fix for this issue, if available. As a temporary workaround, consider restricting access to the change password function to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4385

Affected Products

Letodms