HIGH
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI
Published Oct 17, 2019
8.8
HIGHCVSS 3.1
EPSS 0.60%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.