vendor:
M/Monit
by:
Dolev Farhi
8.8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: M/Monit
Affected Version From: 2.0.151021
Affected Version To: 3.7.2
Patch Exists: YES
Related CWE: N/A
CPE: //a:mmonit:mmonit
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
M/Monit <= 3.7.2 - Privilege Escalation
This exploit allows an unprivileged user to gain admin privileges in M/Monit version 2.0.151021. The exploit uses a POST request to the '/admin/users/update' endpoint with a specially crafted payload. The payload includes the username and password of the unprivileged user, as well as a specially crafted 'oldpassword' parameter. If the request is successful, the unprivileged user will be granted admin privileges.
Mitigation:
Upgrade to M/Monit version 3.7.3 or later.