vendor:
by:
Abysssec Inc
N/A
CVSS
N/A
CSRF, LFI
CWE
Product Name:
Affected Version From: Visinia 1.3
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Visinia Multiple Vulnerabilities
This version of Visinia has multiple vulnerabilities. The first vulnerability is CSRF for Remove Modules, where an attacker can navigate the admin to visit a malicious site to remove a module with a POST request to the server. The second vulnerability is LFI for download web.config or any file.
Mitigation:
Unknown