First published: Wed May 20 2020(Updated: )
In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | <1.2.11 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13231 is a vulnerability in Cacti before version 1.2.11 that allows CSRF for an admin email change.
CVE-2020-13231 has a severity score of 6.5, which is considered medium.
CVE-2020-13231 affects Cacti versions before 1.2.11.
To fix CVE-2020-13231, you should update to Cacti version 1.2.11 or later.
Yes, you can find more information on CVE-2020-13231 at the following references: - GitHub issue: https://github.com/Cacti/cacti/issues/3342 - Cacti release: https://github.com/Cacti/cacti/releases/tag/release%2F1.2.11 - Fedora Project announcement: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ICJMWSY77IIGZYR6FE6NAQZFBO42VECO/