vendor:
None
by:
Security War
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: None
Affected Version From: 0.07
Affected Version To: 0.07
Patch Exists: YES
Related CWE: None
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2020
Security war
This exploit is a Cross-Site Request Forgery (CSRF) vulnerability in the export.php page of the server. The exploit allows an attacker to execute arbitrary code on the server by sending a malicious request to the server. The malicious request contains a form with checkboxes that can be used to select which users to export. The attacker can then submit the form and the server will execute the code with the selected users.
Mitigation:
The best way to mitigate CSRF attacks is to use a CSRF token. A CSRF token is a unique, random string that is generated for each request and is sent as a parameter in the request. The server then checks the token to make sure it is valid before processing the request.