vendor:
CandidATS
by:
J3rryBl4nks
6.8
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: CandidATS
Affected Version From: 2.1.0
Affected Version To: 2.1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:candidats:candidats:2.1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 19/Kali Rolling
2020
CandidATS 2.1.0 – Cross-Site Request Forgery (Add Admin)
The Candid ATS Web application is vulnerable to CSRF to add a new admin user. A proof of concept is provided in the text, which includes a form with hidden inputs that can be used to add a new admin user.
Mitigation:
Implementing a CSRF token in the application can help prevent this type of attack.