vendor:
Cerb
by:
High-Tech Bridge Security Research Lab
5,1
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: Cerb
Affected Version From: 7.0.3
Affected Version To: 7.0.3
Patch Exists: YES
Related CWE: CVE-2015-6545
CPE: a:webgroup_media_llc:cerb
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
HTB23269
High-Tech Bridge Security Research Lab discovered CSRF vulnerability in Cerb platform, which can be exploited to perform Cross-Site Request Forgery attacks against administrators of vulnerable web application to add administrate accounts into the system. The vulnerability exists due to failure of the "/ajax.php" script to properly verify the source of incoming HTTP request.
Mitigation:
Fixed by Vendor