Description
SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-4614 | SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter. |
References
| Link | Providers |
|---|---|
| https://github.com/slims/slims8_akasia/issues/103 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T08:38:06.382Z
Reserved: 2018-06-22T00:00:00.000Z
Link: CVE-2018-12659
No data.
Status : Modified
Published: 2018-06-22T15:29:00.517
Modified: 2024-11-21T03:45:37.970
Link: CVE-2018-12659
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD