Vulnerability Details CVE-2019-17118
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal users or devices.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.2%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2019-17118
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:3.4.81
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:3.4.85
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:3.4.87
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:3.5.0
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:3.6.0
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:4.0
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:4.0.1
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:4.0.2
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:4.1.0
-
cpe:2.3:a:wikidsystems:2fa_enterprise_server:4.2.0