vendor:
PHP Server Monitor
by:
Javier Olmedo
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: PHP Server Monitor
Affected Version From: 3.3.1
Affected Version To: 3.3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:phpservermon:phpservermon:3.3.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows & Ubuntu
2018
PHP Server Monitor 3.3.1 – Cross-Site Request Forgery
PHP Server Monitor version 3.3.1 and possibly before are affected by multiple Cross-Site Request Forgery vulnerability, an attacker could remove users, logs, and servers. The attacker can use Google URL Shortener (or similar) to shorten the malicious URL and send it to the victim, or use a form with hidden inputs to send it to the victim.
Mitigation:
Update to version 3.3.2