vendor:
ABC ERP
by:
Ihsan Sencan
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: ABC ERP
Affected Version From: 0.6.4
Affected Version To: 0.6.4
Patch Exists: NO
Related CWE: N/A
CPE: a:abc-erp:abc_erp:0.6.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
ABC ERP 0.6.4 – Cross-Site Request Forgery (Update Admin)
ABC ERP 0.6.4 is vulnerable to Cross-Site Request Forgery (CSRF) which allows an attacker to update the admin credentials. An attacker can send a malicious request to the vulnerable application which will update the admin credentials without the user's knowledge. This can be exploited by sending a malicious request to the vulnerable application with the new admin credentials.
Mitigation:
Implementing CSRF protection tokens, validating input, and using secure communication protocols can help mitigate this vulnerability.