CVE-2019-25313
MEDIUMFlexNet Publisher 11.12.1 - Cross-Site Request Forgery to Add Local Admin
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25313. PoCs published by Ismail Tasdelen.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in FlexNet Publisher 11.12.1, allowing an attacker to add a local admin user via a crafted HTTP POST request. The PoC includes both the raw HTTP request and an HTML form for easy execution.
Description
FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.
Exploits (1)
This exploit demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in FlexNet Publisher 11.12.1, allowing an attacker to add a local admin user via a crafted HTTP POST request. The PoC includes both the raw HTTP request and an HTML form for easy execution.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N