CVE-2019-19469: CSRF
Published Dec 1, 2019
·Updated
In Zmanda Management Console 3.3.9, ZMCAdminAdvanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.
Affected Software
1 affected component
Zmanda Amanda=3.3.9
Event History
Dec 1, 2019
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19469?
The severity of CVE-2019-19469 is considered high due to its potential for command injection via CSRF.
2
How do I fix CVE-2019-19469?
To fix CVE-2019-19469, ensure that all default credentials are changed and implement CSRF tokens in forms.
3
What version of Zmanda is affected by CVE-2019-19469?
Zmanda version 3.3.9 is affected by CVE-2019-19469.
4
What type of attack does CVE-2019-19469 exploit?
CVE-2019-19469 exploits a Cross-Site Request Forgery (CSRF) vulnerability.
5
Are default credentials a factor in CVE-2019-19469?
Yes, weak default credentials may exacerbate the risk associated with CVE-2019-19469.