vendor:
Driver Manager F454
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
CSRF Change Password Exploit
352
CWE
Product Name: Driver Manager F454
Affected Version From: 1.0.51
Affected Version To: 1.1.14
Patch Exists: NO
Related CWE: N/A
CPE: h:bticino:driver_manager_f454
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Apache/2.2.14 (Unix), OpenSSL/1.0.0d, PHP/5.1.6
2019
Legrand BTicino Driver Manager F454 1.0.51 CSRF Change Password Exploit
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Implementing proper input validation and authentication checks.