vendor:
PHP Advanced Transfer Manager
by:
Paolo Massenio
8,8
CVSS
HIGH
CSRF
352
CWE
Product Name: PHP Advanced Transfer Manager
Affected Version From: <= 1.32
Affected Version To: <= 1.32
Patch Exists: YES
Related CWE: N/A
CPE: a:phpatm:php_advanced_transfer_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 with XAMPP
2016
phpATM <= 1.32 Multiple CSRF Vulnerabilities & Full Path Disclosure Vulnerability
phpATM lets the administrator to modify the footer or the header through a specific form located in configure.php. The configure.php page and all of the forms in it are affected by a CSRF bug, so an attacker can modify the footer.html file, he can inject malicious code in every page of phpATM.
Mitigation:
The administrator should not click on any link sent by an untrusted source.