vendor:
Scopia XT Desktop
by:
v1n1v131r4
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Scopia XT Desktop
Affected Version From: 8.3.915.4
Affected Version To: 8.3.915.4
Patch Exists: NO
Related CWE: N/A
CPE: a:avaya:scopia_xt_desktop:8.3.915.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro
2020
Scopia XT Desktop 8.3.915.4 – Cross-Site Request Forgery (change admin password)
This exploit allows an attacker to change the admin password of the Scopia XT Desktop 8.3.915.4 software to a predefined value. The exploit is achieved by sending a malicious POST request to the directory_settings.jsp page with the newadminpassword parameter set to a predefined value. This will change the admin password to the predefined value.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all user input is properly validated and sanitized before being used in any application logic.