CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2019/Jul/11 | Exploit Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/153581/PowerPanel-Business-Edition-3.4.0-Cross-Site-Request-Forgery.html | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-07-10 07:15
Updated : 2019-10-09 16:46
NVD link : CVE-2019-13071
Mitre link : CVE-2019-13071
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
cyberpowersystems
- powerpanel