PT-2019-7917 · Metinfo · Metinfo
Lemon666
·
Published
2019-05-09
·
Updated
2019-05-09
·
CVE-2017-12790
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Metinfo version 5.3.18
Description
The issue allows for Information Disclosure through a remote attack vector. It involves a Cross Site Request Forgery (CSRF) attack, where the administrator clicks on a malicious link while in a logged-in state. The vulnerable component is the admin/index.php file.
Recommendations
For Metinfo version 5.3.18, as a temporary workaround, consider restricting access to the admin/index.php file until a patch is available. Avoid clicking on suspicious links while logged in to the administrator account to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metinfo