Lucene search

K
githubGitHub Advisory DatabaseGHSA-RRMF-FPMM-JPWR
HistoryMay 17, 2022 - 2:12 a.m.

ViMbAdmin CSRF Vulnerabilities

2022-05-1702:12:38
CWE-352
GitHub Advisory Database
github.com
3

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.1%

Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to hijack the authentication of logged administrators to

  1. add an administrator user via a crafted POST request to <vimbadmin directory>/application/controllers/DomainController.php,
  2. remove an administrator user via a crafted GET request to <vimbadmin directory>/application/controllers/DomainController.php,
  3. change an administrator password via a crafted POST request to <vimbadmin directory>/application/controllers/DomainController.php,
  4. add a mailbox via a crafted POST request to <vimbadmin directory>/application/controllers/MailboxController.php,
  5. delete a mailbox via a crafted POST request to <vimbadmin directory>/application/controllers/MailboxController.php,
  6. archive a mailbox address via a crafted GET request to <vimbadmin directory>/application/controllers/ArchiveController.php,
  7. add an alias address via a crafted POST request to <vimbadmin directory>/application/controllers/AliasController.php, or
  8. remove an alias address via a crafted GET request to <vimbadmin directory>/application/controllers/AliasController.php.

Affected configurations

Vulners
Node
opensolutionsvimbadminRange3.0.15
CPENameOperatorVersion
opensolutions/vimbadminle3.0.15

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.1%