ZeroHour

CVE-2019-13071

PoC ×2
CVSS 3.0
8.8 high
EPSS
<1%p53
Published
()
Modified
Description

CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.

Vendors
cyberpowersystems
Products
powerpanel
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.