CVE-2019-9883: Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account.
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cfnew.cgi?chief=&wkgroup=full&cfname=test&cfaccount=test&cfemail=&cfacl=Management&applylang=&dn= without any authorizes.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this CSRF vulnerability?
The vulnerability ID of this CSRF vulnerability is CVE-2019-9883.
What is the severity of CVE-2019-9883?
The severity of CVE-2019-9883 is high, with a severity value of 8.8.
What software is affected by CVE-2019-9883?
The MailSherlock MSR35 and MSR45 modules are affected by CVE-2019-9883.
How can an attacker exploit CVE-2019-9883?
An attacker can exploit CVE-2019-9883 by using the useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= endpoint to elevate the privilege of a specific account without any authorization.
Is there a fix available for CVE-2019-9883?
It is recommended to update to the latest versions of the affected MailSherlock MSR35 and MSR45 modules to address CVE-2019-9883.