Description
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-3188 | WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner. |
References
| Link | Providers |
|---|---|
| https://seclists.org/bugtraq/2019/Jun/10 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:55:40.659Z
Reserved: 2019-04-25T00:00:00.000Z
Link: CVE-2019-11517
No data.
Status : Modified
Published: 2019-06-10T18:29:00.597
Modified: 2024-11-21T04:21:16.000
Link: CVE-2019-11517
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD