vendor:
T-Soft E-Commerce 4
by:
Alperen Ergel
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: T-Soft E-Commerce 4
Affected Version From: v4
Affected Version To: v4
Patch Exists: NO
Related CWE: None
CPE: a:tsoft:t-soft_e-commerce_4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux (2021.4) / xammp
2021
T-Soft E-Commerce 4 – change ‘admin credentials’ Cross-Site Request Forgery (CSRF)
Attacker can change admin information by sending a malicious POST request to the victimsite.com/srv/service/admin/updateuserinfo with the desired credentials in the request body.
Mitigation:
Implementing a CSRF token in the request body and validating it on the server side.