PT-2019-7917 · Metinfo · Metinfo

Lemon666

·

Published

2019-05-09

·

Updated

2019-05-09

·

CVE-2017-12790

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Metinfo version 5.3.18
Description The issue allows for Information Disclosure through a remote attack vector. It involves a Cross Site Request Forgery (CSRF) attack, where the administrator clicks on a malicious link while in a logged-in state. The vulnerable component is the admin/index.php file.
Recommendations For Metinfo version 5.3.18, as a temporary workaround, consider restricting access to the admin/index.php file until a patch is available. Avoid clicking on suspicious links while logged in to the administrator account to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12790

Affected Products

Metinfo