header-logo
Suggest Exploit
vendor:
GAzie
by:
giudinvx
8,8
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: GAzie
Affected Version From: 5.20
Affected Version To: 5.20
Patch Exists: NO
Related CWE: N/A
CPE: gazie
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012

GAzie <= 5.20 Cross Site Request Forgery

A Cross Site Request Forgery vulnerability exists in GAzie <= 5.20. An attacker can craft a malicious form and submit it to the vulnerable application, which can lead to unintended actions being performed on behalf of the authenticated user. This can be used to modify the application's data, such as changing user credentials, or to perform administrative actions.

Mitigation:

Implementing a CSRF token in the application can help mitigate this vulnerability.
Source

Exploit-DB raw data: