vendor:
CBAS-Web
by:
LiquidWorm
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: CBAS-Web
Affected Version From: 19.0.0
Affected Version To: 19.0.0
Patch Exists: NO
Related CWE: CVE-2019-10847
CPE: a:computrols:cbas-web:19.0.0
Platforms Tested:
2019
CBAS-Web 19.0.0 – Cross-Site Request Forgery (Add Super Admin)
This exploit allows an attacker to perform Cross-Site Request Forgery (CSRF) attack in CBAS-Web version 19.0.0. By tricking a user into visiting a malicious website, the attacker can add a super admin to the system without the user's knowledge or consent.
Mitigation:
To mitigate this vulnerability, users are advised to update to a patched version of CBAS-Web.