vendor:
Knowledge Base
by:
Jelmer de Hen
4,3
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Knowledge Base
Affected Version From: v1.0.0rc3
Affected Version To: v1.0.0rc3
Patch Exists: N/A
Related CWE: N/A
CPE: 68kb
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
68kb Knowledge Base v1.0.0rc3 create administrator account CSRF
This exploit allows an attacker to create an administrator account on the 68kb Knowledge Base v1.0.0rc3 software. The attacker can craft a malicious HTML page that contains a form with hidden fields that contain the username, email, level, password, and passconf of the new account. When the victim visits the malicious page, the form is automatically submitted and the new account is created. The attacker can also use the same technique to delete or edit existing accounts.
Mitigation:
The application should validate the request origin and verify that the user is authorized to perform the requested action.