vendor:
Guppy CMS
by:
Brandon Murphy
7.5
CVSS
HIGH
Authentication Bypass/Change Email
287
CWE
Product Name: Guppy CMS
Affected Version From: 5.0.9
Affected Version To: 5.00.10
Patch Exists: YES
Related CWE: N/A
CPE: a:freeguppy:guppy_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7/Firefox & Xubuntu Linux 3.2.0-23-generic
2015
GuppY CMS 5.0.9 & 5.00.10 Authentication bypass/Change email
This exploit will automatically log you in and change the email to any registered user except for the admin that is installed with the web application. Click on 'Become a member' on the target website to insert the appropriate cookies for this to work. Once the exploit takes place proceed to click 'Modify' and change the password. To see if the user has some sort of admin privileges go to site.com/admin/ while still logged in. If they do it will say 'Vic_username, enter your password:' and login with the password you just changed it to.
Mitigation:
Ensure that authentication is properly implemented and that users are not able to bypass authentication.