CVE-2019-18651

MEDIUM

3xLogic Infinias Access Control <=6.6.9586.0 - CSRF

Title source: llm

Description

A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the website trusts. The user needs to have an active privileged session.

Exploits (1)

gitlab WORKING POC
by crypt0crc · poc
https://gitlab.com/crypt0crc/cve-2019-18651

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-352
Status published
Products (1)
3xlogic/infinias_access_control_firmware < 6.6.9586.0
Published Nov 14, 2019
Tracked Since Feb 18, 2026