Description
CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-19312 | CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests. |
References
| Link | Providers |
|---|---|
| https://crawl3r.xyz/cve/cve-2019-9958/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:10:08.434Z
Reserved: 2019-03-23T00:00:00.000Z
Link: CVE-2019-9958
No data.
Status : Modified
Published: 2019-06-24T19:15:10.867
Modified: 2024-11-21T04:52:40.437
Link: CVE-2019-9958
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD