Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.adive.es/ | product |
https://hackpuntes.com/cve-2019-14346-adive-framework-2-0-7-cross-site-request-forgery/ | third party advisory exploit |
http://packetstormsecurity.com/files/153989/Adive-Framework-2.0.7-Cross-Site-Request-Forgery.html | exploit vdb entry third party advisory |