PT-2019-9459 · Nimble · Nimble Messaging Bulk Sms Marketing Application

Published

2019-06-19

·

Updated

2019-06-21

·

CVE-2018-17387

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nimble Messaging Bulk SMS Marketing Application version 1.0
Description The issue concerns a CSRF problem that allows for the addition of an admin account.
Recommendations For Nimble Messaging Bulk SMS Marketing Application version 1.0, consider temporarily restricting access to the admin account addition functionality until a patch is available.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17387

Affected Products

Nimble Messaging Bulk Sms Marketing Application