Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25242. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates multiple CSRF vulnerabilities in FaceSentry Access Control System 6.4.8, allowing unauthorized actions such as password changes, admin addition, and door opening via crafted HTTP requests.
Description
FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tricking authenticated users into loading a specially crafted webpage.
Exploits (1)
This exploit demonstrates multiple CSRF vulnerabilities in FaceSentry Access Control System 6.4.8, allowing unauthorized actions such as password changes, admin addition, and door opening via crafted HTTP requests.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N