vendor:
b2evolution
by:
saudi0hacker
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: b2evolution
Affected Version From: 3.3.2003
Affected Version To: 3.3.2003
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2010
b2evolution 3.3.3 Cross site request forgery
The b2evolution 3.3.3 application is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can create a malicious HTML page that will make a request to the targeted b2evolution admin panel, tricking the authenticated user into performing unintended actions on their behalf.
Mitigation:
To mitigate this vulnerability, users should implement CSRF protection mechanisms such as using anti-CSRF tokens and validating the referer header in requests.