vendor:
X7 Chat
by:
DennSpec
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: X7 Chat
Affected Version From: 2.0.5.1
Affected Version To: 2.0.5.1
Patch Exists: NO
Related CWE: N/A
CPE: a:x7chat:x7_chat:2.0.5.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
X7 Chat 2.0.5.1 CSRF Add Admin Exploit
This exploit allows an attacker to add an admin user to the X7 Chat 2.0.5.1 application by exploiting a Cross-Site Request Forgery (CSRF) vulnerability. The attacker must first register a user and then send the main page URL to an administrator. The main page URL contains an iframe which contains a form that posts to the application's admin panel page. The form contains the attacker's username and sets the usergroup to 'Administrator'. When the administrator visits the main page URL, the form is automatically submitted and the attacker's user is added as an administrator.
Mitigation:
The application should validate requests to ensure that they are coming from the same origin and not from a malicious third-party. Additionally, the application should use anti-CSRF tokens to ensure that requests are valid.