Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-11393. PoCs published by Dolev Farhi.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in M/Monit by manipulating user update parameters to escalate privileges from an unprivileged user to admin. It uses a hardcoded CSRF token and a default password hash to achieve this.
Description
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
Exploits (1)
This exploit leverages an authentication bypass vulnerability in M/Monit by manipulating user update parameters to escalate privileges from an unprivileged user to admin. It uses a hardcoded CSRF token and a default password hash to achieve this.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H