vendor:
Rukovoditel
by:
KeopssGroup0day,Inc
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Rukovoditel
Affected Version From: 2.6.1
Affected Version To: 2.6.1
Patch Exists: NO
Related CWE: N/A
CPE: a:rukovoditel:rukovoditel:2.6.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2020
Rukovoditel 2.6.1 – Cross-Site Request Forgery (Change password)
A Cross-Site Request Forgery (CSRF) vulnerability exists in Rukovoditel 2.6.1 which allows an attacker to change the password of a user without their knowledge. This is achieved by sending a maliciously crafted request to the vulnerable application. The request contains a form session token and the new password which is set by the attacker. This vulnerability can be exploited by an attacker to gain access to the application.
Mitigation:
The application should implement a CSRF protection mechanism to prevent attackers from exploiting this vulnerability.