vendor:
Multi User Plugin
by:
Bobby Cooke (boku) & Adeeb Shah (@hyd3sec)
7.5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Multi User Plugin
Affected Version From: 1.8.2
Affected Version To: 1.8.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro + XAMPP
2020
GetSimple CMS Plugin Multi User v1.8.2 – Cross-Site Request Forgery (Add Admin)
Cross-Site Request Forgery (CSRF) vulnerability in Multi User v1.8.2 plugin for GetSimple CMS allows remote attackers to add an Admin user via authenticated admin visiting a third-party site.
Mitigation:
The best way to mitigate CSRF attacks is to use a combination of secret tokens and HTTP referrer checks.