CVE-2017-12584: CSRF
There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2 fields in an admin/modules/system/appuser.php changecurrent=true operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12584?
CVE-2017-12584 has a medium severity rating due to its potential for unauthorized account access.
How do I fix CVE-2017-12584?
To mitigate CVE-2017-12584, update to a version of SLiMS subsequent to 8.3.1 that includes Cross-Site Request Forgery (CSRF) protections.
What impact does CVE-2017-12584 have on user accounts?
CVE-2017-12584 allows an attacker to change a user's password without the current password, leading to complete account takeover.
What software is affected by CVE-2017-12584?
CVE-2017-12584 affects SLiMS 8 Akasia through version 8.3.1.
Is there a known exploit for CVE-2017-12584?
Yes, attackers can exploit CVE-2017-12584 by tricking users into changing their passwords to an attacker-controlled one.