PT-2019-9459 · Nimble · Nimble Messaging Bulk Sms Marketing Application
Published
2019-06-19
·
Updated
2019-06-21
·
CVE-2018-17387
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nimble Messaging Bulk SMS Marketing Application version 1.0
Description
The issue concerns a CSRF problem that allows for the addition of an admin account.
Recommendations
For Nimble Messaging Bulk SMS Marketing Application version 1.0, consider temporarily restricting access to the admin account addition functionality until a patch is available.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nimble Messaging Bulk Sms Marketing Application