CVE-2019-11393: Critical severity monit vulnerability
Published Apr 21, 2019
·Updated
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
Affected Software
1 affected component
Tildeslash Monit<3.7.3
Event History
Apr 21, 2019
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11393?
CVE-2019-11393 is classified as a high severity vulnerability allowing privilege escalation.
2
How do I fix CVE-2019-11393?
To fix CVE-2019-11393, upgrade M/Monit to version 3.7.3 or later.
3
Who is affected by CVE-2019-11393?
Unprivileged users of M/Monit versions prior to 3.7.3 are affected by CVE-2019-11393.
4
What type of vulnerability is CVE-2019-11393?
CVE-2019-11393 is a privilege escalation vulnerability.
5
What can attackers do with CVE-2019-11393?
Attackers can use CVE-2019-11393 to escalate their privileges to that of an administrator.