vendor:
Tickets CAD
by:
chap0 @_chap0
8,8
CVSS
HIGH
Reflective/Stored XSS, Information Disclosure and CSRF
79, 200, 352
CWE
Product Name: Tickets CAD
Affected Version From: 2.20G
Affected Version To: 2.20G
Patch Exists: YES
Related CWE: N/A
CPE: ticketscad:tickets_cad:2.20g
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu
2012
Tickets CAD 2.20G Multiple Vulnerabilities
Tickets CAD 2.20G is vulnerable to multiple vulnerabilities including Reflective/Stored XSS, information disclosure and CSRF. While logged in even with the default guest/guest credentials, the guest user is able to store and execute arbitrary JavaScript code withing the application. Information disclosure also exist, the application does not properly check which user is currently logged in. Finally CSRF is also possible within the Tickets CAD application which allows an attacker to successfully add an admin account.
Mitigation:
The vulnerabilities can be prevented by using strip_tags.