CVE-2019-11077: CSRF
Published Apr 11, 2019
·Updated
FastAdmin V1.0.0.20190111beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.
Affected Software
1 affected component
fastadmin FastAdmin=1.0.0.20190111-beta
Event History
Apr 11, 2019
CVE Published
via MITRE·01:10 AM
Data Sourced
via MITRE·01:10 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11077?
The severity of CVE-2019-11077 has been rated as medium due to its potential for unauthorized access to admin functionality.
2
How do I fix CVE-2019-11077?
To fix CVE-2019-11077, implement CSRF tokens in your forms to protect against cross-site request forgery.
3
Who is affected by CVE-2019-11077?
CVE-2019-11077 affects users of FastAdmin version 1.0.0.20190111_beta.
4
What kind of attack can exploit CVE-2019-11077?
CVE-2019-11077 can be exploited through cross-site request forgery, allowing an attacker to add new admin users without authentication.
5
Can CVE-2019-11077 be exploited remotely?
Yes, CVE-2019-11077 can be exploited remotely if specific conditions are met, allowing an attacker to gain unauthorized administrative access.