Vulnerability Description
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tildeslash | Monit | < 3.7.3 |
Related Weaknesses (CWE)
References
- https://mmonit.com/wiki/MMonit/Release3-7-3Release NotesVendor Advisory
- https://www.exploit-db.com/exploits/46404ExploitThird Party AdvisoryVDB Entry
- https://mmonit.com/wiki/MMonit/Release3-7-3Release NotesVendor Advisory
- https://www.exploit-db.com/exploits/46404ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-11393?
CVE-2019-11393 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the...
How severe is CVE-2019-11393?
CVE-2019-11393 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-11393?
Check the references section above for vendor advisories and patch information. Affected products include: Tildeslash Monit.