685
VMScore

CVE-2018-11538

Published: 01/06/2018 Updated: 03/07/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.

Vulnerable Product Search on Vulmon Subscribe to Product

searchblox searchblox 8.6.6

Vendor Advisories

Check Point Reference: CPAI-2018-2730 Date Published: 28 Mar 2024 Severity: High ...

Exploits

# Exploit Title: CSRF Privilege Escalation (Creation of an administrator account) on SearchBlox 866 # Exploit Author: Canberk BOLAT, Ahmet GÜREL # Software Link: wwwsearchbloxcom/ # Version: < = SearchBlox Version 866 # Platform: Java # Tested on: Windows # CVE: CVE-2018-11538 # 1 DETAILS Using Cross-Site Request Forgery (CSRF) ...
SearchBlox version 866 suffers from a cross site request forgery vulnerability ...