vendor:
All-Dynamics Digital Signage System
by:
LiquidWorm
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: All-Dynamics Digital Signage System
Affected Version From: 2.0.2
Affected Version To: 2.0.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: enlogic:show server, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows Server 2012, Microsoft Windows 10, GNU/Linux, Apache, PHP
2020
All-Dynamics Digital Signage System 2.0.2 – Cross-Site Request Forgery (Add Admin)
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Implement proper CSRF protection mechanisms, such as using anti-CSRF tokens, to validate and verify the authenticity of each request.