vendor:
PHPfileNavigator
by:
John Page aka hyp3rlinx
8.8
CVSS
HIGH
CSRF add arbitrary user accounts
352
CWE
Product Name: PHPfileNavigator
Affected Version From: 2.3.2003
Affected Version To: 2.3.2003
Patch Exists: YES
Related CWE: N/A
CPE: pfn.sourceforge.net
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: xampp-1.7.0
2013
PHPfileNavigator v2.3.3 (pfn) CSRF add arbitrary user accounts
No CSRF token exists when creating user accounts, this allows us to exploit the application and add arbitrary users The ?PHPSESSID= cookie used in URL is useless as we can just replace the value with whatever.
Mitigation:
The vendor released a patch to address this vulnerability.