vendor:
Mars Stelaer
by:
Sköll
7.4
CVSS
HIGH
Admin Account Takeover
287
CWE
Product Name: Mars Stelaer
Affected Version From: < 8.3
Affected Version To: 8.3
Patch Exists: YES
Related CWE:
CPE: a:mars_stealer:mars_stealer
Platforms Tested: Linux
2023
Mars Stealer 8.3 – Admin Account Takeover
Mars Stealer is vulnerable to an admin account takeover exploit. This exploit allows an attacker to change the admin password of the application using a POST request to the settingsactions.php file. The attacker can then use the new password to gain access to the application.
Mitigation:
Ensure that the application is updated to the latest version of Mars Stealer 8.3 or higher.