CSRF Vulnerability in MyT Project Management 1.5.1 Allows Arbitrary Code Execution

CSRF Vulnerability in MyT Project Management 1.5.1 Allows Arbitrary Code Execution

CVE-2019-15496 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.

Learn more about our User Device Pen Test.