PT-2023-10833 · Unknown · Mdalamin-Aol Own Health Record

Mdalamin-Aol

·

Published

2023-12-30

·

Updated

2024-05-17

·

CVE-2018-25096

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MdAlAmin-aol Own Health Record versions 0.1-alpha through 0.3.1-alpha
Description This issue affects some unknown processing of the file includes/logout.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely.
Recommendations For MdAlAmin-aol Own Health Record versions 0.1-alpha through 0.3.1-alpha, upgrade to version 0.4-alpha to address this issue. As a temporary workaround, consider restricting access to the includes/logout.php file until the upgrade is applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2018-25096

Affected Products

Mdalamin-Aol Own Health Record