First published: Sun Aug 06 2017(Updated: )
There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2 fields in an admin/modules/system/app_user.php changecurrent=true operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Library Management System | <=8.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12584 has a medium severity rating due to its potential for unauthorized account access.
To mitigate CVE-2017-12584, update to a version of SLiMS subsequent to 8.3.1 that includes Cross-Site Request Forgery (CSRF) protections.
CVE-2017-12584 allows an attacker to change a user's password without the current password, leading to complete account takeover.
CVE-2017-12584 affects SLiMS 8 Akasia through version 8.3.1.
Yes, attackers can exploit CVE-2017-12584 by tricking users into changing their passwords to an attacker-controlled one.