vendor:
Nimble Professional - Mobile Marketing Text Blast Web Application
by:
Ihsan Sencan
7,5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Nimble Professional - Mobile Marketing Text Blast Web Application
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:ranksol:nimble_professional_-_mobile_marketing_text_blast_web_application
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2017
Nimble Professional – Mobile Marketing Text Blast Web Application 1.0 – Cross-Site Request Forgery (Update Admin)
This vulnerability allows an attacker to update the admin profile of Nimble Professional - Mobile Marketing Text Blast Web Application 1.0. An attacker can craft a malicious HTML page containing a form with the necessary parameters and submit it to the vulnerable application. This will allow the attacker to update the admin profile with the provided values.
Mitigation:
The application should validate the origin of the request and ensure that the request is coming from a trusted source.