vendor:
Banner Experience Pro
by:
nukedx
7,5
CVSS
HIGH
Unauthorized Admin Add Exploit
264
CWE
Product Name: Banner Experience Pro
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Jiros Banner Experience Pro Unauthorized Admin Add Exploit
This exploit allows an attacker to add an admin account to the Jiros Banner Experience Pro application without authorization. The attacker can use the given dork to find vulnerable sites and then use the exploit to add an admin account with the given username, email, and password. The exploit is triggered when the attacker submits the form.
Mitigation:
Ensure that only authorized users are able to add admin accounts to the application.