vendor:
Feng Office
by:
High-Tech Bridge SA - Ethical Hacking & Penetration Testing
3.3
CVSS
LOW
CSRF (Cross-Site Request Forgery)
352
CWE
Product Name: Feng Office
Affected Version From: 1.7.3.3
Affected Version To: Prior Versions
Patch Exists: NO
Related CWE: N/A
CPE: a:secure_data_srl:feng_office
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
XSRF/CSRF in Feng Office
The vulnerability exists due to failure in the users editing script to properly verify the source of HTTP request. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data. Attacker can use browser to exploit this vulnerability.
Mitigation:
The application should verify the source of HTTP request.