Vulnerability Details CVE-2019-12890
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.529
EPSS Ranking 97.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-12890
-
cpe:2.3:a:redwoodhq:redwoodhq:2.0
-
cpe:2.3:a:redwoodhq:redwoodhq:2.5.5