vendor:
Windu CMS
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Windu CMS
Affected Version From: 2.2 rev 1430
Affected Version To: 2.2 rev 1430
Patch Exists: NO
Related CWE: N/A
CPE: a:adam_czajkowski:windu_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Ultimate SP1 (EN), Apache 2.4.2 (Win32), PHP 5.4.7, MySQL 5.5.25a
2013
Windu CMS 2.2 CSRF Add Admin Exploit
Windu CMS suffers from a cross-site request forgery vulnerability. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Validate all user input and perform proper authentication checks.