vendor:
Enigma NMS
by:
Mark Cross
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Enigma NMS
Affected Version From: Enigma NMS 65.0.0
Affected Version To: Enigma NMS 65.0.0
Patch Exists: YES
Related CWE: CVE-2019-16068
CPE: a:netsas:enigma_nms:65.0.0
Platforms Tested:
2019
Enigma NMS Cross-Site Request Forgery (CSRF)
The following CSRF will create a PHP file for executing a reverse shell on port 1337 via the user upload functionality within the NMS web application.
Mitigation:
Implement CSRF tokens, Validate user input, and Restrict file upload functionality