CVE-2018-15539: CSRF
Published Oct 15, 2018
·Updated
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
Affected Software
1 affected component
Agentejo Cockpit
Event History
Oct 15, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-15539?
CVE-2018-15539 is a vulnerability in Agentejo Cockpit that allows an attacker to change API tokens, passwords, etc.
2
How severe is CVE-2018-15539?
CVE-2018-15539 has a severity rating of 8.8 (high).
3
Does Agentejo Cockpit lack an anti-CSRF protection mechanism?
Yes, Agentejo Cockpit lacks an anti-CSRF protection mechanism.
4
What can an attacker do with CVE-2018-15539?
With CVE-2018-15539, an attacker is able to change API tokens, passwords, etc.
5
Is there a fix for CVE-2018-15539?
There is no known fix for CVE-2018-15539 at the moment. It is recommended to take additional security measures.