MyT Project Management 1.5.1 CSRF

by Vince
in Blog
Hits: 7493

Disclosure date:  8/19/19

CVE-2019-15496

MyT Project Management 1.5.1 and possibly before are affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection.  This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.

Read more

LibreNMS v1.54 XSS

by Vince
in Blog
Hits: 7518

Disclosure date:  08/19/19

CVE-2019-15230

LibreNMS v1.54 and possibly before are affected by numerous Cross Site Script vulnerabilities in the "Create User", "Inventory", "Add Device", "Notifications", "Alert Rule", "Create Maintenance", "Alert Template", and "Alert Template" sections of the admin console.  This could lead to cookie stealing and other malicious actions.  This vulnerability can be exploited with an authenticated account.  

Read more

FuelCMS 1.4.4 CSRF

by Vince
in Blog
Hits: 7455

Disclosure date:  08/17/19

CVE-2019-15229

FuelCMS 1.4.4 and possibly before are affected by a Cross Site Request Forgery vulnerability in the Create Blocks section of the Admin console.  This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.

Read more