Warehouse Inventory System 1.0 – Cross-Site Request Forgery (Change Admin Password) – Digitalmunition




Exploit/Advisories 1596732310_spider-orange.png

Published on August 10th, 2020 📆 | 4696 Views ⚑

0

Warehouse Inventory System 1.0 – Cross-Site Request Forgery (Change Admin Password)

# Exploit Title: Warehouse Inventory System 1.0 - Cross-Site Request Forgery (Change Admin Password)
# Exploit Author: Bobby Cooke (boku) & Adeeb Shah (@hyd3sec)
# Date: 2020-08-09
# Vendor Homepage:  https://oswapp.com
# Software Link: https://github.com/siamon123/warehouse-inventory-system/archive/master.zip
# Version: 1.0
# Tested On: Windows 10 Pro + XAMPP | Python 2.7
# CWE-352: Cross-Site Request Forgery (CSRF)
# CVSS Base Score: 7.5 # Impact Subscore: 5.9 # Exploitability Subscore: 1.6
# Vulnerability Description:
#   Cross-Site Request Forgery (CSRF) vulnerability in 'edit_user.php' webpage of OSWAPP's 
#   Warehouuse Inventory System v1.0 allows remote attackers to change the admins password
#   via authenticated admin visiting a third-party site.


  

Source link

Tagged with:



Leave a Reply

Your email address will not be published. Required fields are marked *


loading...