Record summary

CVE-2019-12890 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBRedwoodHQ 2.5.5 - Authentication BypassExploitDB exploitby EthicalHCOPNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubEthicalHCOP/CVE-2019-12890_RedxploitHQRepository PoCby EthicalHCOPStars: 0Not analyzed1 file

2.6 KiB

GitHub

PoC details

References

3