vendor:
Customer Support System
by:
Ahmed Abbas
7.5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Customer Support System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro 1909 (x64_86) + XAMPP 7.4.4
2020
Customer Support System 1.0 – Cross-Site Request Forgery (Admin Account Takeover)
The username and password parameters can be forged to force the password change of admin user account.
Mitigation:
Implement CSRF protection mechanisms such as using anti-CSRF tokens and validating requests.