PT-2020-10306 · Selesta · Selesta Visual Access Manager
Published
2020-02-26
·
Updated
2020-02-27
·
CVE-2019-19987
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Selesta Visual Access Manager (VAM) versions 4.15.0 through 4.29
Description
The issue allows Cross-Site Request Forgery (CSRF) on any HTML form, enabling an attacker to abuse functionalities such as changing passwords, adding users, adding privileges, and more.
Recommendations
For versions 4.15.0 through 4.29, consider implementing CSRF protection mechanisms, such as token-based validation, to prevent exploitation of the vulnerable HTML forms. As a temporary workaround, restrict access to sensitive functionalities like change password, add user, and add privilege until a proper fix is applied.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Selesta Visual Access Manager