CVE-2019-25313: FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)
FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25313?
CVE-2019-25313 has a high severity rating due to its potential for unauthorized administrative access.
How do I fix CVE-2019-25313?
To fix CVE-2019-25313, update FlexNet Publisher to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2019-25313?
CVE-2019-25313 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2019-25313?
CVE-2019-25313 affects users of FlexNet Publisher version 11.12.1.
What can attackers do if CVE-2019-25313 is exploited?
If exploited, attackers can create administrative user accounts without authentication in FlexNet Publisher.