Vulnerability Description
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netsas | Enigma Network Management Solution | <= 65.0.0 |
Related Weaknesses (CWE)
References
- https://www.mogozobo.com/?p=3647ExploitVendor Advisory
- https://www.mogozobo.com/?p=3647ExploitVendor Advisory
FAQ
What is CVE-2019-16068?
CVE-2019-16068 is a vulnerability with a CVSS score of 8.8 (HIGH). A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be tr...
How severe is CVE-2019-16068?
CVE-2019-16068 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16068?
Check the references section above for vendor advisories and patch information. Affected products include: Netsas Enigma Network Management Solution.