vendor:
TypeSetter
by:
Alperen Ergel
6.8
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: TypeSetter
Affected Version From: 5.1
Affected Version To: 5.1
Patch Exists: NO
Related CWE: N/A
CPE: a:typesettercms:typesetter
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali & Ubuntu
2020
TypeSetter 5.1 – CSRF (Change admin e-mail)
Attacker can change admin e-mail address by sending a POST request to the admin page view preferences and changing the e-mail address.
Mitigation:
Implementing CSRF protection tokens, using HTTPS, and validating input can help mitigate CSRF attacks.