vendor:
Diferior CMS
by:
10n1z3d
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Diferior CMS
Affected Version From: 8.03
Affected Version To: 8.03
Patch Exists: NO
Related CWE: N/A
CPE: a:diferior:diferior_cms:8.03
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Diferior CMS 8.03 Multiple CSRF Vulnerabilities
Diferior CMS 8.03 is vulnerable to multiple CSRF vulnerabilities. An attacker can exploit these vulnerabilities to change the admin password, change the admin email address, and ban a user. The attacker can also change the password and email address of other users by changing the value of the 'cust_user' parameter in the POST request.
Mitigation:
The application should use a CSRF token to verify the authenticity of the request.