vendor:
Proton/Enterprise BMS
by:
LiquidWorm
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Proton/Enterprise BMS
Affected Version From: <=2.3.0a
Affected Version To: <=2.3.0a
Patch Exists: YES
Related CWE: CVE-2019-7273
CPE: optergy:proton_enterprise_bms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Optergy 2.3.0a – Cross-Site Request Forgery (Add Admin)
Optergy Proton/Enterprise BMS is vulnerable to Cross-Site Request Forgery (CSRF) which allows an attacker to add an admin user to the system. An attacker can craft a malicious HTML page containing a form with the necessary parameters to add an admin user to the system. When a logged-in user visits the malicious page, the form will be automatically submitted and an admin user will be added to the system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of the software.