header-logo
Suggest Exploit
vendor:
4images
by:
Or4nG.M4n
8,8
CVSS
HIGH
Cross-site request forgery (CSRF)
352
CWE
Product Name: 4images
Affected Version From: 1.7.6
Affected Version To: 9
Patch Exists: NO
Related CWE: N/A
CPE: a:4homepages:4images
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

4images 1.7.6 > 9 Csrf inject php code

This exploit allows an attacker to inject malicious code into the 4images 1.7.6 > 9 web application. The attacker can use a form to send a malicious payload to the vulnerable application, which will then be executed on the server. The payload can be used to execute arbitrary commands on the server, allowing the attacker to gain access to sensitive information or take control of the server.

Mitigation:

The best way to mitigate CSRF attacks is to use a combination of security measures, such as using anti-CSRF tokens, implementing same-site cookies, and using a Content Security Policy (CSP).
Source

Exploit-DB raw data: