VulnerabilityModified
CVE-2020-8439
Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to the users/21/edit URI.
MEDIUM 6.5EPSS 1.59%
Does this matter?
Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.
Description
Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to the users/21/edit URI.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-425
- Affected
- monstra/monstra
- Source
- cve@mitre.org
References
- http://uploadboy.me/cn40ne6p89t6/POC.mp4.htmlExploit, Third Party Advisory
- https://cert.ikiu.ac.ir/public-files/pages/attachments/11/02630f153869936d555a79f89d717f9c.pdfMitigation, Third Party Advisory
- http://uploadboy.me/cn40ne6p89t6/POC.mp4.htmlExploit, Third Party Advisory
- https://cert.ikiu.ac.ir/public-files/pages/attachments/11/02630f153869936d555a79f89d717f9c.pdfMitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.