vendor:
eMerge E3
by:
LiquidWorm
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: eMerge E3
Affected Version From: 1.00-06
Affected Version To: 1.00-06
Patch Exists: YES
Related CWE: CVE-2019-7262
CPE: a:linear_solutions:emerge_e3:1.00-06
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2018
eMerge E3 1.00-06 – Cross-Site Request Forgery
Nortek Linear eMerge E3 Access Control Cross-Site Request Forgery is a vulnerability that allows an attacker to perform malicious actions on behalf of a legitimate user. This vulnerability can be exploited by sending a maliciously crafted request to the vulnerable system. The malicious request can be used to add a super user, change the admin password, or perform other malicious actions.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to apply the patch as soon as possible.