vendor:
Saurus CMS
by:
Fady Mohammed Osman
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Saurus CMS
Affected Version From: 4.7.0
Affected Version To: 4.7.0
Patch Exists: NO
Related CWE: Not available
CPE: a:saurus:saurus_cms:4.7.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 10.04
2020
Saurus CMS 4.7.0 CSRF Vulnerability
Saurus CMS 4.7.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows a malicious hacker to change the password of a user and also change the website information. The PoC 1 demonstrates how a malicious hacker can change the website information, while the PoC 2 demonstrates how a malicious hacker can change the user's password.
Mitigation:
The website should implement a CSRF token to verify the authenticity of the request.