vendor:
PHP-Twitter-Clone
by:
L0RD
3.1
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: PHP-Twitter-Clone
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:fyffe:php-twitter-clone
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win 10
2018
Twitter-Clone 1 – Cross-Site Request Forgery (Delete Post)
An issue was discovered in Twitter-Clone 1 which allows a remote attacker to force any victim to delete posts. The attacker can craft a malicious HTML page with a form that submits to the tweetdel.php page with the ID of the post they want to delete. When the victim visits the page, the form is automatically submitted and the post is deleted.
Mitigation:
Implementing a CSRF token on the form to prevent unauthorized requests.