Tildeslash M Monit vulnerabilities
2 known vulnerabilities affecting tildeslash/m_monit.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-36968HIGHCVSS 7.1v3.7.42026-01-28
CVE-2020-36968 [HIGH] CWE-522 CVE-2020-36968: M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrie
M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5 password hashes for all users.
nvd
CVE-2020-36969HIGHCVSS 8.7v3.7.42026-01-28
CVE-2020-36969 [HIGH] CWE-863 CVE-2020-36969: M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modif
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.
nvd