vendor:
ScriptCase
by:
hyp3rlinx
8,8
CVSS
HIGH
CSRF Remote Command Execution, CSRF Add Admin, SQL Injection, Cross Site Scripting, Local Privlege Escalation (Insecure File Permissions), User Enumeration / Token Bypass
352, 89, 79, 264, 285
CWE
Product Name: ScriptCase
Affected Version From: v8.1.053
Affected Version To: v8.1.43.0
Patch Exists: YES
Related CWE: N/A
CPE: a:scriptcase:scriptcase
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2019
ScriptCase PHP Web Tool Multiple Vulnerabilities
ScriptCase is vulnerable to multiple security issues, including CSRF Remote Command Execution, CSRF Add Admin, SQL Injection, Cross Site Scripting, Local Privlege Escalation (Insecure File Permissions), and User Enumeration / Token Bypass. An attacker can exploit these vulnerabilities to gain access to the application and modify files, add an arbitrary system account to the affected system, and execute arbitrary system commands on the affected host.
Mitigation:
ScriptCase should be installed with secure file permissions, and users should be aware of the potential for CSRF attacks.