vendor:
RV Shopping cart
by:
DaOne
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: RV Shopping cart
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
RV Shopping cart CSRF Vulnerability
This exploit allows an attacker to add an admin user to the RV Shopping cart application. The attacker can craft a malicious HTML page with a form that contains the necessary parameters to add an admin user. When the victim visits the malicious page, the form is automatically submitted and the admin user is added to the application.
Mitigation:
Implementing CSRF protection tokens, validating the HTTP Referer header, and using CAPTCHA can help mitigate CSRF attacks.