vendor:
diafan.CMS
by:
High-Tech Bridge SA - Ethical Hacking & Penetration Testing
3.3
CVSS
LOW
CSRF and XSS
352 (Cross-Site Request Forgery) and 79 (Cross-site Scripting)
CWE
Product Name: diafan.CMS
Affected Version From: 4.3
Affected Version To: 4.3 and probably prior versions
Patch Exists: NO
Related CWE: N/A
CPE: diafan.CMS
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Browser
2010
HTB22777
The vulnerability exists due to failure in the "http://host/admin/usersite/save2/" script to properly verify the source of HTTP request and to properly sanitize user-supplied input. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data. Attacker can use browser to exploit this vulnerability.
Mitigation:
The application should verify the source of HTTP request and properly sanitize user-supplied input.