Back to search
CVE-2014-6607
Published: Oct 6, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via the fullname and password parameters, a different vulnerability than CVE-2014-6409.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20140919 M/Monit - Account hijacking via CSRF
mailing-list
x_refsource_FULLDISC
34718
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now