Vulnerability Details CVE-2019-9688
sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2019-9688
-
cpe:2.3:a:sftnow:sftnow:2016-07-18
-
cpe:2.3:a:sftnow:sftnow:2016-07-19
-
cpe:2.3:a:sftnow:sftnow:2016-07-20
-
cpe:2.3:a:sftnow:sftnow:2016-07-21
-
cpe:2.3:a:sftnow:sftnow:2016-07-25
-
cpe:2.3:a:sftnow:sftnow:2016-07-26
-
cpe:2.3:a:sftnow:sftnow:2016-07-27
-
cpe:2.3:a:sftnow:sftnow:2016-07-28
-
cpe:2.3:a:sftnow:sftnow:2016-07-29
-
cpe:2.3:a:sftnow:sftnow:2016-07-31
-
cpe:2.3:a:sftnow:sftnow:2016-08-17
-
cpe:2.3:a:sftnow:sftnow:2016-08-18
-
cpe:2.3:a:sftnow:sftnow:2016-11-30
-
cpe:2.3:a:sftnow:sftnow:2017-08-15
-
cpe:2.3:a:sftnow:sftnow:2018-12-29