vendor:
Open-AuditIT Professional
by:
Nilesh Sapariya
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Open-AuditIT Professional
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: CVE-2018-8979
CPE: a:open-audit:open-auditit:2.1
Platforms Tested: Windows 10 Pro
2018
Open-AuditIT Professional 2.1 – Cross-Site Request Forgery (CSRF)
There is no CSRF protection in Open-AuditIT application, with a little help of social engineering (like sending a link via email/chat) an attacker may force the victim to click on a malicious link by which any normal user can become an Admin user. The attack can force an end user to execute unwanted actions on a web application in which they're currently authenticated. Using this vulnerability, we were able to compromise entire user account with chaining this bug with XSS.
Mitigation:
Implement CSRF protection in the Open-AuditIT application to prevent unauthorized actions by authenticated users.