PT-2020-12867 · Rukovoditel · Rukovoditel

Published

2020-04-16

·

Updated

2020-04-22

·

CVE-2020-11818

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rukovoditel version 2.5.2
Description The protection mechanism in place to prevent CSRF attacks can be bypassed by an attacker using another user's valid form session token value. This allows the attacker to perform a CSRF attack, potentially changing the Admin password and escalating their privileges.
Recommendations For Rukovoditel version 2.5.2, consider temporarily disabling the ability to change the Admin password through the form until a patch is available, or restrict access to the form to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11818

Affected Products

Rukovoditel