8.8
CVSSv3

CVE-2019-14346

Published: 06/08/2019 Updated: 13/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schben adive 2.0.7

Exploits

# Exploit Title: Adive Framework 207 – Cross-Site Request Forgery (CSRF) # Date:02/08/2019 # Exploit Author: Pablo Santiago # Vendor Homepage: adivees # Software Link: githubcom/ferdinandmartin/adive-php7 # Version: 207 # Tested on: Windows and Kali linux # CVE :2019-14346 # 1 Technical Description: # Adive Framework 20 ...
Adive Framework version 207 suffers from a cross site request forgery vulnerability ...