index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/155242/RISE-Ultimate-Project-Manager-2.3-Cross-Site-Request-Forgery.html | Exploit Third Party Advisory VDB Entry |
https://codecanyon.net/item/rise-ultimate-project-manager/15455641 | Product |
Configurations
Information
Published : 2019-11-13 12:15
Updated : 2019-11-19 08:15
NVD link : CVE-2019-18884
Mitre link : CVE-2019-18884
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
fairsketch
- rise_-_ultimate_project_manager