vendor:
Typesetter CMS
by:
Navina Asrani
3.1
CVSS
MEDIUM
Cross Site Request Forgery
352
CWE
Product Name: Typesetter CMS
Affected Version From: 5.1
Affected Version To: 5.1
Patch Exists: NO
Related CWE: NA
CPE: a:typesettercms:typesetter_cms:5.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Webapp CMS
2018
TypeSetter CMS 5.1 Cross Site Request Forgery
The application allows malcious HTTP requests to be directly executed without any hidden security token.This may lead to user account takeover or malious command execution
Mitigation:
Enforce security tokens such as anti csrf tokens.