vendor:
MySms
by:
AtT4CKxT3rR0r1ST
5.5
CVSS
MEDIUM
Multiple
CWE
Product Name: MySms
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
MySms v1.0 Multiple Vulnerabilities
The text describes two vulnerabilities in the MySms v1.0 application. The first vulnerability is an Authentication Bypass, which allows an attacker to bypass authentication by using a specific input. The second vulnerability is Cross-Site Request Forgery (CSRF), which allows an attacker to perform unauthorized actions on behalf of a user.
Mitigation:
The vendor should release a patch to fix the authentication bypass vulnerability and implement proper CSRF protection.