vendor:
onArcade v2.4.2
by:
r3m0t3nu11[Zero-way]
N/A
CVSS
N/A
Cross-Site Request Forgery
CSRF
CWE
Product Name: onArcade v2.4.2
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2018
Cross-Site Request Forgery (Add Admin)
The application is vulnerable to CSRF attack (No CSRF token in place) meaning that if an admin user can be tricked to visit a crafted URL created by attacker (via spear phishing/social engineering).
Mitigation:
Implement CSRF tokens in the application to prevent CSRF attacks.