vendor:
Modern POS
by:
Ihsan Sencan
7.5
CVSS
HIGH
Arbitrary File Download
22
CWE
Product Name: Modern POS
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE: N/A
CPE: a:itsolution24:modern_pos:1.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
Modern POS 1.3 – Arbitrary File Download
Modern POS 1.3 is vulnerable to arbitrary file download. An attacker can exploit this vulnerability by sending a crafted HTTP request to the target server. The request should contain the action parameter set to download and the path parameter set to the file that the attacker wants to download. This vulnerability can be exploited to download sensitive files such as configuration files, which can lead to further attacks.
Mitigation:
The vendor should ensure that the application does not allow users to download arbitrary files.