CVE Vulnerabilities

CVE-2019-11018

Improper Authentication

Published: Apr 08, 2019 | Modified: Dec 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

applicationadmincontrollerUser.php in ThinkAdmin V4.0 does not prevent continued use of an administrators cookie-based credentials after a password change.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Thinkadmin Thinkadmin 4.0 (including) 4.0 (including)

Potential Mitigations

References