vendor:
Precurio Intranet Portal
by:
Ihsan Sencan
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Precurio Intranet Portal
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: a:precurio:precurio_intranet_portal
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
Precurio Intranet Portal 2.0 – Cross-Site Request Forgery (Add Admin)
Precurio Intranet Portal 2.0 is vulnerable to Cross-Site Request Forgery (CSRF) which allows an attacker to add an admin user to the portal. An attacker can craft a malicious request to add an admin user to the portal. The malicious request can be sent to the victim via email, chat, etc. When the victim clicks on the malicious link, the attacker can add an admin user to the portal.
Mitigation:
Implement CSRF protection tokens to verify the authenticity of the request.