vendor:
Gnew
by:
Cyril Vallicari / HTTPCS - ZIWIT
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Gnew
Affected Version From: 2018.1
Affected Version To: 2018.1
Patch Exists: NO
Related CWE: N/A
CPE: a:gnew:gnew:2018.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home x64 / Kali Linux
2018
Gnew 2018.1 – Cross-Site Request Forgery
A vulnerability has been discovered in Gnew , which can be exploited by malicious people to conduct cross-site request forgery attacks. This can be used to get a privilege escalation on the targeted application.
Mitigation:
Implementing a security policy that prohibits the use of untrusted URLs and implementing a CSRF token to verify the authenticity of the request.