vendor:
E-Store 1.0
by:
AtT4CKxT3rR0r1ST
5.5
CVSS
MEDIUM
XSRF
352
CWE
Product Name: E-Store 1.0
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
E-Store 1.0 XSRF Vulnerability (Add Admin)
This exploit allows an attacker to add an admin user to the E-Store 1.0 application by sending a crafted HTTP request. The attacker can specify the username, password, email, and group ID for the new admin user.
Mitigation:
To mitigate this vulnerability, it is recommended to implement CSRF tokens in the application to validate the authenticity of requests.