vendor:
M/Monit
by:
Dolev Farhi
4,3
CVSS
MEDIUM
CSRF
352
CWE
Product Name: M/Monit
Affected Version From: <= 3.2.2
Affected Version To: <= 3.2.2
Patch Exists: NO
Related CWE: N/A
CPE: a:mmonit:mmonit:3.2.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
M/Monit CSRF
It was found that M/Monit latest version is vulnerable to CSRF attacks. it is possible to reset the password of any user account (admin/regular) on the system without needing to know the current set password for the attacked account.
Mitigation:
Implementing a CSRF token in the application can prevent this type of attack.