vendor:
CloverDX Server
by:
niebardzo
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: CloverDX Server
Affected Version From: 5.4.x
Affected Version To: 5.9.0
Patch Exists: YES
Related CWE: CVE-2021-29995
CPE: a:cloverdx:cloverdx_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Docker
2021
CloverDX 5.9.0 – Cross-Site Request Forgery (CSRF) to Remote Code Execution (RCE)
CloverDX 5.9.0 is vulnerable to Cross-Site Request Forgery (CSRF) to Remote Code Execution (RCE). An attacker can exploit this vulnerability by sending a malicious request to the target server. The attacker can use the ViewStateCracker.java to crack the ViewState and gain access to the target server. This vulnerability affects versions 5.9.0, 5.8.1, 5.8.0, 5.7.0, 5.6.x, 5.5.x, 5.4.x.
Mitigation:
The user should ensure that the ViewState is properly encrypted and that the server is not vulnerable to CSRF attacks.