vendor:
Sharetronix CMS
by:
Hesam Bazvand
5.5
CVSS
MEDIUM
XSRF
352
CWE
Product Name: Sharetronix CMS
Affected Version From: 3.6.2002
Affected Version To: 3.6.2002
Patch Exists: NO
Related CWE:
CPE: a:sharetronix:cms:3.6.2
Platforms Tested: Windows 10, Kali Linux
Sharetronix CMS XSRF Vulnerability
This exploit takes advantage of a cross-site request forgery (XSRF) vulnerability in Sharetronix CMS version 3.6.2. By tricking a user into visiting a malicious website, an attacker can perform actions on behalf of the victim without their consent or knowledge. In this specific exploit, the attacker submits a form with hidden fields that contain malicious code to the target Sharetronix CMS installation, causing it to execute the code and display an alert box.
Mitigation:
To mitigate this vulnerability, users should update their Sharetronix CMS installation to the latest version available. Additionally, users should be cautious when clicking on links or visiting unfamiliar websites.