vendor:
NXFilter
by:
hyp3rlinx
7,5
CVSS
HIGH
Cross site request forgery - CSRF
352
CWE
Product Name: NXFilter
Affected Version From: NXFilter v3.0.3
Affected Version To: NXFilter v3.0.3
Patch Exists: Yes
Related CWE: N/A
CPE: a:nxfilter:nxfilter
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2015
NXFilter v3.0.3 CSRF
No CSRF protections exist allowing us to make malicious HTTP requests on behalf of our victim. The Server will then happily process any of the following actions if our victim clicks our infected linx or visits our malicious website while currently logged in to the vulnerable application. 1) 'add arbitrary users' 2) 'add or change SMTP settings' 3) 'add arbitrary redirect domains' 4) 'add arbitrary zone transfers' 5) 'delete zone transfer domains'
Mitigation:
Ensure CSRF protections are in place.