vendor:
UniFi Controller, mFi Controller, and AirVision Controller
by:
Seth Art
8,8
CVSS
HIGH
CSRF
352
CWE
Product Name: UniFi Controller, mFi Controller, and AirVision Controller
Affected Version From: v2.4.6, v2.0.15, v2.1.3
Affected Version To: Previous versions
Patch Exists: YES
Related CWE: CVE-2014-2225
CPE: a:ubnt:unifi_controller
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux
2014
Cross-site Request Forgery (CSRF)
A Cross-site Request Forgery (CSRF) vulnerability exists in UniFi Controller, mFi Controller, and AirVision Controller versions prior to v2.4.6, v2.0.15, and v2.1.3 respectively. An attacker can exploit this vulnerability to add an admin user to the controller without authentication. The attacker can then use the newly created admin user to gain access to the controller.
Mitigation:
Upgrade to the latest version of UniFi Controller, mFi Controller, and AirVision Controller.