PT-2017-12170 · Hashtopus · Hashtopus

Ghost

·

Published

2017-07-27

·

Updated

2017-08-03

·

CVE-2017-11679

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hashtopus version 1.5g
Description A Cross-Site Request Forgery (CSRF) issue exists, allowing unauthorized actions via the password parameter to "admin.php" in an "a=config" action.
Recommendations For version 1.5g, consider restricting access to the "admin.php" endpoint to minimize the risk of exploitation, and avoid using the password parameter in this endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11679

Affected Products

Hashtopus