vendor:
Advanced Electron Forum v1.0.9 (AEF)
by:
hyp3rlinx
7,5
CVSS
HIGH
Remote File Inclusion / CSRF
N/A
CWE
Product Name: Advanced Electron Forum v1.0.9 (AEF)
Affected Version From: 1.0.9
Affected Version To: 1.0.9
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Advanced Electron Forum v1.0.9 (AEF) Remote File Inclusion / CSRF Vulnerability
Advanced Electron Forum v1.0.9 (AEF) is vulnerable to Remote File Inclusion / CSRF. In Admin control panel there is option to Import Skins and one choice is using a web URL. However there is no CSRF token or check made that this is a valid request made by the currently logged in user, resulting in arbitrary remote file imports from an attacker if the user visits or clicks an malicious link. Victims will then be left open to arbitrary malicious file downloads from anywhere on the net which may be used as a platform for further attacks...
Mitigation:
Upgrade to latest version.