index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/155242/RISE-Ultimate-Project-Manager-2.3-Cross-Site-Request-Forgery.html | Exploit Third Party Advisory VDB Entry |
https://codecanyon.net/item/rise-ultimate-project-manager/15455641 | Product |
http://packetstormsecurity.com/files/155242/RISE-Ultimate-Project-Manager-2.3-Cross-Site-Request-Forgery.html | Exploit Third Party Advisory VDB Entry |
https://codecanyon.net/item/rise-ultimate-project-manager/15455641 | Product |
Configurations
History
21 Nov 2024, 04:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/155242/RISE-Ultimate-Project-Manager-2.3-Cross-Site-Request-Forgery.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://codecanyon.net/item/rise-ultimate-project-manager/15455641 - Product |
Information
Published : 2019-11-13 20:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18884
Mitre link : CVE-2019-18884
CVE.ORG link : CVE-2019-18884
JSON object : View
Products Affected
fairsketch
- rise_-_ultimate_project_manager
CWE
CWE-352
Cross-Site Request Forgery (CSRF)