CVE-2017-11726: CSRF
Published Jul 31, 2017
·Updated
services/systemio/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by changing an e-mail address setting.
Affected Software
1 affected component
ConnectWise Manage=2017.5
Event History
Jul 31, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11726?
CVE-2017-11726 is classified as a moderate severity vulnerability due to its potential impact on user account settings.
2
How do I fix CVE-2017-11726?
To fix CVE-2017-11726, upgrade ConnectWise Manage to a version beyond 2017.5 that addresses this CSRF vulnerability.
3
What type of vulnerability is CVE-2017-11726?
CVE-2017-11726 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What is affected by CVE-2017-11726?
CVE-2017-11726 affects ConnectWise Manage version 2017.5.
5
What can an attacker do with CVE-2017-11726?
An attacker exploiting CVE-2017-11726 could change email address settings without user consent.