CVE-2019-13071
Summary
| CVE | CVE-2019-13071 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-10 14:15:00 UTC |
| Updated | 2019-10-09 23:46:00 UTC |
| Description | CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cyberpowersystems | Powerpanel | 3.4.0 | All | All | All |
| Application | Cyberpowersystems | Powerpanel | 3.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PowerPanel Business Edition 3.4.0 Cross Site Request Forgery ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory |
| Full Disclosure: PowerPanel Business Edition 3.4.0 - Cross Site Request Forgery | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.