CVE-2019-17118
17.10.2019, 18:15
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal users or devices.
Vendor | Product | Version |
---|---|---|
wikidsystems | 2fa_enterprise_server | 3.4.81:b676 |
wikidsystems | 2fa_enterprise_server | 3.4.85:b780 |
wikidsystems | 2fa_enterprise_server | 3.4.87:b1092 |
wikidsystems | 2fa_enterprise_server | 3.4.87:b1159 |
wikidsystems | 2fa_enterprise_server | 3.4.87:b1169 |
wikidsystems | 2fa_enterprise_server | 3.4.87:b1216 |
wikidsystems | 2fa_enterprise_server | 3.4.87:b824 |
wikidsystems | 2fa_enterprise_server | 3.4.87:b839 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1342 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1352 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1359 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1373 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1403 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1411 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1421 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1428 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1438 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1472 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1542 |
wikidsystems | 2fa_enterprise_server | 3.5.0:b1580 |
wikidsystems | 2fa_enterprise_server | 3.6.0:b1659 |
wikidsystems | 2fa_enterprise_server | 3.6.0:b1672 |
wikidsystems | 2fa_enterprise_server | 4.0:b1787 |
wikidsystems | 2fa_enterprise_server | 4.0:b1798 |
wikidsystems | 2fa_enterprise_server | 4.0:b1803 |
wikidsystems | 2fa_enterprise_server | 4.0.1:b1817 |
wikidsystems | 2fa_enterprise_server | 4.0.1:b1821 |
wikidsystems | 2fa_enterprise_server | 4.0.1:b1905 |
wikidsystems | 2fa_enterprise_server | 4.0.1:b1906 |
wikidsystems | 2fa_enterprise_server | 4.0.2:b1917 |
wikidsystems | 2fa_enterprise_server | 4.0.2:b1921 |
wikidsystems | 2fa_enterprise_server | 4.1.0:b1926 |
wikidsystems | 2fa_enterprise_server | 4.1.0:b1941 |
wikidsystems | 2fa_enterprise_server | 4.1.0:b1949 |
wikidsystems | 2fa_enterprise_server | 4.1.0:b1955 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b1978 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b1981 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b1984 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2007 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2014 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2016 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2020 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2023 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2028 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2032 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2047 |
wikidsystems | 2fa_enterprise_server | 4.2.0:b2053 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References