CVE-2019-25313

F

lexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.

Configurations

No configuration.

History

12 Feb 2026, 15:10

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 21:16

Updated : 2026-02-12 15:10


NVD link : CVE-2019-25313

Mitre link : CVE-2019-25313

CVE.ORG link : CVE-2019-25313


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)