vendor:
User Registration & Login and User Management System
by:
Dipak Panchal(th3.d1p4k)
6.8
CVSS
MEDIUM
Cross Site Request Forgery
352
CWE
Product Name: User Registration & Login and User Management System
Affected Version From: 2.1
Affected Version To: 5
Patch Exists: NO
Related CWE: N/A
CPE: 2.1:5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
User Registration & Login and User Management System 2.1 – Cross Site Request Forgery
An attacker can craft HTML page containing POST information to have the victim sign into an attacker's account, where the victim can add information assuming he/she is logged into the correct account, where in reality, the victim is signed into the attacker's account where the changes are visible to the attacker.
Mitigation:
Please add a csrf token to login request or make some type prompt that the session has ended when the new login from attacker occurs.