vendor:
Movies Library
by:
AtT4CKxT3rR0r1ST
5.5
CVSS
MEDIUM
XSRF
Cross-Site Request Forgery (CSRF)
CWE
Product Name: Movies Library
Affected Version From: Movies Library 2.0
Affected Version To: Movies Library 2.0
Patch Exists: NO
Related CWE:
CPE: a:movies_library:2.0
Platforms Tested:
Unknown
Movies Library 2.0 XSRF Vulnerability (Add Admin)
This exploit allows an attacker to add an admin user to the Movies Library 2.0 application. The attacker can send a crafted request to the targeted application, which will add a new user with admin privileges.
Mitigation:
To mitigate this vulnerability, developers should implement proper CSRF protection mechanisms such as using anti-CSRF tokens or checking the origin of the request.