PT-2019-9461 · Unknown · Live Call Support Application

Published

2019-06-19

·

Updated

2019-06-20

·

CVE-2018-17389

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Live Call Support Application version 1.5
Description The issue exists in the server.php file, allowing for the addition of an admin account due to CSRF.
Recommendations For version 1.5, update the server.php file to include proper CSRF protection mechanisms, such as token validation, to prevent unauthorized admin account additions.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17389

Affected Products

Live Call Support Application