6
CVSSv2

CVE-2017-7571

Published: 06/04/2017 Updated: 01/04/2021
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ladybirdweb faveo helpdesk 1.9.3

Exploits

# Exploit Title: CSRF / Privilege Escalation (Manipulation of Role Agent to Admin) on Faveo version Community 193 # Google Dork: no # Date: 05-April-2017 # Exploit Author: @rungga_reksya, @yokoacc, @AdyWikradinata, @dickysofficial, @dvnrcy # Vendor Homepage: wwwfaveohelpdeskcom/ # Software Link: codeloadgithubcom/ladybirdweb/fa ...