vendor:
Stark CRM
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Multiple stored XSS and CSRF vulnerabilities
352
CWE
Product Name: Stark CRM
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:iwcn_systems_inc:stark_crm:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Nginx, PHP, MySQL
2014
Stark CRM v1.0 Multiple Script Injection And Session Riding Vulnerabilities
The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site and/or execute arbitrary HTML and script code in a user's browser session.
Mitigation:
Validate user input and perform checks to verify the requests.