vendor:
Model Agency Media House & Model Gallery
by:
Borna nematzadeh (L0RD)
7.5
CVSS
HIGH
Persistent Cross-Site Scripting / Cross-Site Request Forgery / Authentication bypass
79, 352, 287
CWE
Product Name: Model Agency Media House & Model Gallery
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:codecanyon:model_agency_media_house_&_model_gallery:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
Model Agency Media House & Model Gallery 1.0 – Persistent Cross-Site Scripting / Cross-Site Request Forgery / Authentication bypass
Model Agency - Media House & Model Gallery 1.0 suffers from multiple vulnerabilities. For Persistent Cross-Site Scripting, after creating an account, go to the profile and navigate to 'Update profile' and put the payload '/><script>alert(document.domain)</script>'. For Cross-Site Request Forgery, the attacker can use a form with hidden inputs to submit the data. For Authentication bypass, the attacker can bypass the admin panel without any authentication by using the username ' or 0=0 #' and any password.
Mitigation:
Implement input validation, use secure authentication methods, use secure communication protocols, use secure session management, use secure data storage, use secure coding practices, use secure access control.