vendor:
MP C4504ex
by:
Ismail Tasdelen
8.8
CVSS
HIGH
Code Injection
352
CWE
Product Name: MP C4504ex
Affected Version From: MP C4504ex
Affected Version To: MP C4504ex
Patch Exists: YES
Related CWE: CVE-2018-15884
CPE: h:ricoh:mp_c4504ex
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
RICOH MP C4504ex Printer – Cross-Site Request Forgery (Add Admin)
A Cross-Site Request Forgery (CSRF) vulnerability has been discovered on the printer of MP C4504ex of RICOH product. Low priviliage users are able to create administrator accounts.
Mitigation:
Implementing a CSRF token in the application can prevent CSRF attacks.