vendor:
Tina4 Stack
by:
Ihsan Sencan
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Tina4 Stack
Affected Version From: 1.0.3
Affected Version To: 1.0.3
Patch Exists: NO
Related CWE: N/A
CPE: a:tina4:tina4_stack:1.0.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
Tina4 Stack 1.0.3 – Cross-Site Request Forgery (Update Admin)
Tina4 Stack 1.0.3 is vulnerable to Cross-Site Request Forgery (CSRF) which allows an attacker to update the admin credentials. An attacker can craft a malicious request to update the admin credentials and gain access to the admin panel. This vulnerability can be exploited without authentication.
Mitigation:
Implementing CSRF protection tokens, validating the origin of the request, and using a secure connection can help mitigate this vulnerability.