First published: Thu Oct 17 2019(Updated: )
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Metinfo Metinfo | =7.0.0-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17676 is a vulnerability in MetInfo 7.0.0beta that allows a CSRF attack to add a user account.
The CVE-2019-17676 vulnerability can be exploited by performing a CSRF attack to add a user account via a specific action in the admin/index.php file.
The severity of CVE-2019-17676 is rated as high, with a severity value of 8.8.
To fix the CVE-2019-17676 vulnerability, it is recommended to update MetInfo to a version that includes the necessary security patches.
More information about CVE-2019-17676 can be found at the following reference: https://github.com/anx1ang/notes/issues/1