vendor:
Croogo
by:
Milos Zivanovic
7,5
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: Croogo
Affected Version From: 1.2.1
Affected Version To: 1.2.1
Patch Exists: NO
Related CWE: N/A
CPE: a:croogo:croogo:1.2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2010
Croogo 1.2.1 Multiple CSRF Vulnerabilities
Croogo blog script lacks of cross site request forgery protection, allowing us to make exploit to add new admin user or change existing admin password.
Mitigation:
Implementing CSRF protection on the application.