PT-2017-18632 · Simple Invoices · Simple Invoices

Tgianko

·

Publicado

2017-05-14

·

Atualizado

2017-05-25

·

CVE-2017-8930

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Invoices version 2013.1.beta.8
Description The issue allows remote attackers to hijack the authentication of admins for requests. This can lead to creating new administrator user accounts and taking over the entire application, creating regular user accounts, or changing configuration parameters such as tax rates and the enable/disable status of PayPal payment modules.
Recommendations For Simple Invoices version 2013.1.beta.8, consider implementing proper CSRF protection mechanisms to prevent authentication hijacking, such as token-based validation for sensitive operations like creating new administrator or regular user accounts, and modifying configuration parameters.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8930

Produtos afetados

Simple Invoices