vendor:
flatCore-CMS
by:
CodeSecLab
6.1
CVSS
HIGH
Cross Site Request Forgery (CSRF)
352
CWE
Product Name: flatCore-CMS
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE: CVE-2019-13961
CPE: a:flatcore:flatcore:1.5
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=122231, https://www.infosecmatter.com/nessus-plugin-library/?id=145893, https://www.infosecmatter.com/nessus-plugin-library/?id=131096, https://www.infosecmatter.com/nessus-plugin-library/?id=130792, https://www.infosecmatter.com/nessus-plugin-library/?id=123770, https://www.infosecmatter.com/nessus-plugin-library/?id=122533, https://www.infosecmatter.com/nessus-plugin-library/?id=123113, https://www.infosecmatter.com/nessus-plugin-library/?id=121576, https://www.infosecmatter.com/nessus-plugin-library/?id=157619
Platforms Tested: Ubuntu, Windows
2024
flatCore 1.5 – Cross Site Request Forgery (CSRF)
The exploit allows an attacker to perform Cross Site Request Forgery (CSRF) on flatCore version 1.5. By tricking an authenticated user into visiting a malicious website, the attacker can upload files to the server due to lack of proper CSRF protection. This vulnerability has been assigned CVE-2019-13961.
Mitigation:
Implementing proper CSRF tokens and origin checks can help mitigate this vulnerability in flatCore version 1.5.