PT-2019-9843 · Webgalamb · Webgalamb
Daniel Jones
·
Published
2019-03-17
·
Updated
2020-08-24
·
CVE-2018-19511
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Webgalamb version 7.0
Description
The issue concerns a lack of security measures to prevent CSRF attacks. This can be demonstrated through the API endpoint "wg7.php?options=1" which allows changing the administrator password.
Recommendations
For Webgalamb version 7.0, consider implementing proper CSRF protection mechanisms to prevent unauthorized changes to sensitive settings, such as the administrator password. As a temporary workaround, restrict access to the "wg7.php" endpoint to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webgalamb