vendor:
eWallet - Online Payment Gateway
by:
L0RD
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: eWallet - Online Payment Gateway
Affected Version From: 2
Affected Version To: 2
Patch Exists: N/A
Related CWE: N/A
CPE: a:codecanyon:ewallet_online_payment_gateway
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
eWallet – Online Payment Gateway 2 – Cross-Site Request Forgery
eWallet - Online Payment Gateway 2 suffers from csrf vulnerability. Attacker can send target account balance to his account.
Mitigation:
Implementing a random token in the request and validating it on the server side can prevent CSRF attacks.