vendor:
School ERP System
by:
J3rryBl4nks
6.5
CVSS
MEDIUM
Cross Site Request Forgery
352
CWE
Product Name: School ERP System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2020-8504, CVE-2020-8505
CPE: a:school_erp_ultimate:1.0
Platforms Tested: Windows 10, Kali Rolling
2020
School ERP System 1.0 – Cross Site Request Forgery (Add Admin)
The School ERP Ultimate web application is vulnerable to Cross Site Request Forgery that leads to admin account creation and arbitrary user deletion.
Mitigation:
Implement CSRF tokens to validate requests and prevent Cross Site Request Forgery attacks.