CVE-2019-18651
MEDIUM3xLogic Infinias Access Control <=6.6.9586.0 - CSRF
Title source: llmDescription
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the website trusts. The user needs to have an active privileged session.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.0011
EPSS Percentile
30.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-352
Status
published
Products (1)
3xlogic/infinias_access_control_firmware
< 6.6.9586.0
Published
Nov 14, 2019
Tracked Since
Feb 18, 2026