vendor:
SynaMan
by:
Marlow Tannhauser
7.5
CVSS
HIGH
CSRF/Stored XSS
352
CWE
Product Name: SynaMan
Affected Version From: 3.4 Build 1436
Affected Version To: 3.4 Build 1436
Patch Exists: Yes
Related CWE: 2015-3140
CPE: a:synametrics:synaman:3.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Multiple vulnerabilities in SynaMan 3.4 Build 1436 (CSRF/Stored XSS)
SynaMan 3.4 Build 1436 is vulnerable to CSRF attacks, which can also be combined with stored XSS attacks (authenticated administrators only). The JSESSIONID created when a user logs on to the system is persistent and does not change across requests. The following PoC uses the CSRF vulnerability together with one of the stored XSS vulnerabilities, to create a new shared folder in the application. The following PoC uses the CSRF vulnerability to create a new user with the details shown.
Mitigation:
The vendor has released a patch to address the vulnerabilities.