← Back

CVE-2019-17118

nvd nist
Published: Oct 17, 2019Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal users or devices.

Affected (47)

1 product
2fa Enterprise Server
Configuration A
47 vulnerable
Vulnerable SoftwareAffected Versions
Wikidsystems
Version 3.4.81 b676
Version 3.4.85 b780
Version 3.4.87 b1092
Version 3.4.87 b1159
Version 3.4.87 b1169
Version 3.4.87 b1216
Version 3.4.87 b824
Version 3.4.87 b839
Version 3.5.0 b1342
Version 3.5.0 b1352
Version 3.5.0 b1359
Version 3.5.0 b1373
Version 3.5.0 b1403
Version 3.5.0 b1411
Version 3.5.0 b1421
Version 3.5.0 b1428
Version 3.5.0 b1438
Version 3.5.0 b1472
Version 3.5.0 b1542
Version 3.5.0 b1580
Version 3.6.0 b1659
Version 3.6.0 b1672
Version 4.0.1 b1817
Version 4.0.1 b1821
Version 4.0.1 b1905
Version 4.0.1 b1906
Version 4.0.2 b1917
Version 4.0.2 b1921
Version 4.0 b1787
Version 4.0 b1798
Version 4.0 b1803
Version 4.1.0 b1926
Version 4.1.0 b1941
Version 4.1.0 b1949
Version 4.1.0 b1955
Version 4.2.0 b1978
Version 4.2.0 b1981
Version 4.2.0 b1984
Version 4.2.0 b2007
Version 4.2.0 b2014
Version 4.2.0 b2016
Version 4.2.0 b2020
Version 4.2.0 b2023
Version 4.2.0 b2028
Version 4.2.0 b2032
Version 4.2.0 b2047
Version 4.2.0 b2053

References (8)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch

Timeline

No history available yet.