vendor:
M/Monit
by:
Dolev Farhi
8.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: M/Monit
Affected Version From: 3.7.4
Affected Version To: 3.7.4
Patch Exists: YES
Related CWE: N/A
CPE: a:mmonit:mmonit:3.7.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
M/Monit 3.7.4 – Privilege Escalation
This exploit is a privilege escalation vulnerability in M/Monit 3.7.4. It allows an attacker to gain administrator privileges by sending a POST request to the '/api/1/admin/users/update' endpoint with the username, fullname, password, and admin flag set to 1. This will allow the attacker to gain full access to the M/Monit application.
Mitigation:
Ensure that the application is running the latest version of M/Monit and that all users have the least privileges necessary to perform their tasks.