FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password. | |
| Title | FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin) | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T20:49:47.374Z
Reserved: 2026-02-11T14:31:05.505Z
Link: CVE-2019-25313
No data.
Status : Received
Published: 2026-02-11T21:16:03.550
Modified: 2026-02-11T21:16:03.550
Link: CVE-2019-25313
No data.
OpenCVE Enrichment
No data.
Weaknesses