CVE-2019-9883
Summary
| CVE | CVE-2019-9883 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-03 18:29:00 UTC |
| Updated | 2019-10-09 23:53:00 UTC |
| Description | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hgiga | Msr35 Isherlock-base | All | All | All | All |
| Application | Hgiga | Msr35 Isherlock-base | All | All | All | All |
| Application | Hgiga | Msr35 Isherlock-sysinfo | All | All | All | All |
| Application | Hgiga | Msr35 Isherlock-sysinfo | All | All | All | All |
| Application | Hgiga | Msr35 Isherlock-user | All | All | All | All |
| Application | Hgiga | Msr35 Isherlock-user | All | All | All | All |
| Application | Hgiga | Msr35 Isherlock-useradmin | All | All | All | All |
| Application | Hgiga | Msr35 Isherlock-useradmin | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-base | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-base | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-sysinfo | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-sysinfo | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-user | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-user | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-useradmin | All | All | All | All |
| Application | Hgiga | Msr45 Isherlock-useradmin | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TWCERT/CC 台灣電腦網路危機處理暨協調中心 | MISC | surl.twcert.org.tw | Exploit, Third Party Advisory |
| 台灣漏洞紀錄平台 Taiwan Vulnerability Note | MISC | tvn.twcert.org.tw | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: AurOraD@d
There are currently no legacy QID mappings associated with this CVE.