vendor:
Warehouse Inventory System
by:
Bobby Cooke (boku) & Adeeb Shah (@hyd3sec)
7.5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Warehouse Inventory System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro + XAMPP | Python 2.7
2020
Warehouse Inventory System 1.0 – Cross-Site Request Forgery (Change Admin Password)
Cross-Site Request Forgery (CSRF) vulnerability in 'edit_user.php' webpage of OSWAPP's Warehouse Inventory System v1.0 allows remote attackers to change the admin's password via authenticated admin visiting a third-party site.
Mitigation:
Implement CSRF tokens to prevent CSRF attacks.