vendor:
Oxwall
by:
High-Tech Bridge Security Research Lab
7.13.0
CVSS
HIGH
Cross-Site Request Forgery [CWE-352]
352
CWE
Product Name: Oxwall
Affected Version From: 1.7.4
Affected Version To: 1.7.4
Patch Exists: YES
Related CWE: CVE-2015-5534
CPE: a:oxwall:oxwall:1.7.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Oxwall CSRF Vulnerability
The vulnerability exists due to failure in the "/admin/pages/maintenance" script to properly verify the source of the HTTP request. A remote attacker can trick a logged-in administrator to visit a page with CSRF exploit and put the entire website under maintenance. Additionally, the attacker is able to inject arbitrary HTML and JavaScript code into maintenance message and execute it in browsers of any website visitor. Successful exploitation of this vulnerability may allow an attacker to steal other users’ cookies, spread malware to website visitors, and even obtain full control over vulnerable website.
Mitigation:
Fixed by Vendor