CVE-2024-48846
HIGHABB ASPECT/MATRIX/NEXUS Firmware < 3.08.03 - Cross-Site Request Forgery
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48846. PoCs published by LiquidWorm.
AI-analyzed exploit summary This HTML file demonstrates a CSRF vulnerability in ABB Cylon Aspect's userManagement.php, allowing unauthorized user addition or deletion via crafted POST requests. The PoC includes forms targeting both PHP and Java endpoints.
Description
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
Exploits (1)
This HTML file demonstrates a CSRF vulnerability in ABB Cylon Aspect's userManagement.php, allowing unauthorized user addition or deletion via crafted POST requests. The PoC includes forms targeting both PHP and Java endpoints.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N