vendor:
FlexNet Publisher
by:
Ismail Tasdelen
8.8
CVSS
HIGH
Cross-Site Request Forgery (Add Local Admin)
352
CWE
Product Name: FlexNet Publisher
Affected Version From: v11.12.1
Affected Version To: v11.12.1
Patch Exists: YES
Related CWE: N/A
CPE: a:flexera_software:flexnet_publisher
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux, Windows
2019
FlexNet Publisher 11.12.1 – Cross-Site Request Forgery (Add Local Admin)
A Cross-Site Request Forgery (CSRF) vulnerability exists in FlexNet Publisher 11.12.1 which allows an attacker to add a local admin user. An attacker can send a malicious HTTP request to the vulnerable server to add a local admin user. This can be exploited by an attacker to gain access to the vulnerable server.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update to the latest version of FlexNet Publisher.