vendor:
chatNow
by:
HaHwul
3,5
CVSS
MEDIUM
CSRF and Reflected XSS
352, 79
CWE
Product Name: chatNow
Affected Version From: Latest commit
Affected Version To: Latest commit
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian [wheezy]
2016
chatNow – Multiple Vulnerabilities
'send_message.php' is not check the csrf token or referer header. It is possible CSRF Attack. This page url is reflected data on page. It is vulnerable page because not filtered reflected url.
Mitigation:
Implement CSRF token and filter the reflected data.