vendor:
HRSALE
by:
Ismail Akici
N/A
CVSS
N/A
Cross-Site Request Forgery (Add Admin)
CWE
Product Name: HRSALE
Affected Version From: 1.1.2008
Affected Version To: 1.1.2008
Patch Exists: NO
Related CWE:
CPE: a:hrsale:hrsale:1.1.8
Platforms Tested:
2020
HRSALE 1.1.8 – Cross-Site Request Forgery (Add Admin)
CSRF vulnerability was discovered in v1.1.8 version of HRSALE. With this vulnerability, authorized users can be added to the system.
Mitigation:
Unknown