Vulnerability Description
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Monitorr | Monitorr | 1.7.6m |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/163263/Monitorr-1.7.6m-Bypass-Information-DExploitThird Party AdvisoryVDB Entry
- https://lyhinslab.org/index.php/2020/09/12/how-the-white-box-hacking-works-authoExploitThird Party Advisory
- https://www.exploit-db.com/exploits/48981ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/163263/Monitorr-1.7.6m-Bypass-Information-DExploitThird Party AdvisoryVDB Entry
- https://lyhinslab.org/index.php/2020/09/12/how-the-white-box-hacking-works-authoExploitThird Party Advisory
- https://www.exploit-db.com/exploits/48981ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-28872?
CVE-2020-28872 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
How severe is CVE-2020-28872?
CVE-2020-28872 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-28872?
Check the references section above for vendor advisories and patch information. Affected products include: Monitorr Monitorr.