vendor:
Infinity Market Classified Ads Script
by:
L0RD
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Infinity Market Classified Ads Script
Affected Version From: 1.6.2
Affected Version To: 1.6.2
Patch Exists: YES
Related CWE: N/A
CPE: a:codecanyon:infinity_market_classified_ads_script:1.6.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
Infinity Market Classified Ads Script 1.6.2 – Cross-Site Request Forgery
CSRF vulnerability allows attacker to change user's information directly. The POC provided shows an example of how an attacker can craft a malicious HTML form to change a user's information.
Mitigation:
Implementing a CSRF token in the HTML form to verify the authenticity of the request.