vendor:
Crypto Currency Tracker (CCT)
by:
0xBr
8.1
CVSS
CRITICAL
Admin Account Creation
CWE
Product Name: Crypto Currency Tracker (CCT)
Affected Version From: <=9.5
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2023-37759
CPE:
Platforms Tested:
2023
Crypto Currency Tracker (CCT) 9.5 – Admin Account Creation (Unauthenticated)
The Crypto Currency Tracker (CCT) version 9.5 allows unauthenticated users to create an admin account by sending a specially crafted POST request to the /en/user/register endpoint. This vulnerability can be exploited by an attacker to gain unauthorized administrative access to the application.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the software that fixes the issue. Additionally, access to the /en/user/register endpoint should be restricted to authorized users only.