vendor:
Help Request System
by:
G13
7.5
CVSS
HIGH
Cross-Site Request Forgery (XSRF)
352
CWE
Product Name: Help Request System
Affected Version From: 1.1g
Affected Version To: 1.1g
Patch Exists: NO
Related CWE: N/A
CPE: freehelpdesk.org
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Help Request System 1.1g XSRF (add admin)
This exploit allows an attacker to add an admin user to the Help Request System 1.1g application by submitting a maliciously crafted form. The form contains fields for the user's name, login name, and password, as well as a hidden field for the user's level. By setting the user's level to 0, the attacker can create an admin user.
Mitigation:
The application should validate all user input and verify that the user is authorized to perform the requested action.