vendor:
Advanced Electron Forum
by:
hyp3rlinx
N/A
CVSS
N/A
CSRF
352
CWE
Product Name: Advanced Electron Forum
Affected Version From: 1.0.9
Affected Version To: 1.0.9
Patch Exists: YES
Related CWE: N/A
CPE: a:anelectron:advanced_electron_forum
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2019
Advanced Electron Forum v1.0.9 (AEF) CSRF Vulnerability
In Admin panel no CSRF protections exist in multiple areas allowing remote attackers to make HTTP request on behalf of the victim if they currently have a valid session (logged in) and visit or click an infected link, resulting in some of the following destructions. Change current database settings, Delete all Inbox / Sent Emails, Delete all 'shouts', Delete all Topics, edit profile, avatar and more all seem vulnerable as well.
Mitigation:
Implement CSRF protection in the Admin panel.