vendor:
PHP Server Monitor
by:
hyp3rlinx
7.5
CVSS
HIGH
Cross site request forgery (CSRF)
352
CWE
Product Name: PHP Server Monitor
Affected Version From: PHP Server Monitor 3.1.1
Affected Version To: PHP Server Monitor 3.1.1
Patch Exists: NO
Related CWE:
CPE: a:phpservermonitor:php_server_monitor:3.1.1
Platforms Tested:
PHP Server Monitor 3.1.1 Cross Site Request Forgery (CSRF) Vulnerability
Multiple CSRF issues in PHP Server Monitor allow remote attackers to add arbitrary users & servers to the system, modify system configurations and delete arbitrary servers, if user (admin) is logged in and visits our malicious website or clicks on our infected links. As no CSRF protection is used in the application, we can make requests on the victim's behalf and the server will happily oblige processing our malicious HTTP requests.
Mitigation:
No mitigation available at the moment.