Application: M/Monit 3.2.2 Author: Dolev Farhi @dolevff Date: 13.9.2014 Relevant CVEs: CVE-2014-6409, CVE-2014-6607 Vulnerable version: <= 3.2.2 M/Monit is an Easy, proactive monitoring of Unix systems, network and cloud services. 1. Vulnerability Description: Account hijack via cross-site request forgery (CVE-2014-6409, CVE-2014-6607) It was found that M/Monit latest version is vulnerable to CSRF attacks. it is possible to reset the password of any user account (admin/user) on the system without needing to know the current password of the attacked account, due to missing password change verification mechanism. 2. Proof of concept
CSRF poc M/monit