PT-2019-19743 · Php Scripts Mall · Php Scripts Mall Online Lottery Php Readymade Script

Aniket Dinda

·

Published

2019-03-29

·

Updated

2019-04-01

·

CVE-2019-9604

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP Scripts Mall Online Lottery PHP Readymade Script version 1.7.0
Description The issue concerns a Cross-Site Request Forgery (CSRF) flaw related to Edit Profile actions.
Recommendations For PHP Scripts Mall Online Lottery PHP Readymade Script version 1.7.0, consider implementing proper CSRF token validation for the Edit Profile action to prevent unauthorized changes.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9604

Affected Products

Php Scripts Mall Online Lottery Php Readymade Script