vendor:
Commentics
by:
Jean Pascal Pereira
7,5
CVSS
HIGH
Cross Site Scripting, Cross Site Request Forgery / File Deletion
79,352
CWE
Product Name: Commentics
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:commentics:commentics:2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Commentics 2.0 <= Multiple Vulnerabilities
The whole administration interface is prone to several client-side attacks. Examples of the attacks include file deletion vulnerability, Cross Site Scripting, CSRF/Change admin email and password, and CSRF/Add new admin user.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in any operation.