vendor:
Dating Pro
by:
High-Tech Bridge Security Research Lab
8.83.09.63.0
CVSS
CRITICAL
Cross-Site Request Forgery [CWE-352]
352
CWE
Product Name: Dating Pro
Affected Version From: Genie (2015.7)
Affected Version To: Genie (2015.7)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
CSRF in Dating Pro
A remote unauthenticated attacker can create a specially crafted malicious web page with CSRF exploit, trick a logged-in administrator to visit the page, spoof the HTTP request as if it was coming from the legitimate user, and change login, email address and password of the current website administrator.
Mitigation:
Validate HTTP request origin in "/admin/ausers/index" script.