PT-2019-19743 · Php Scripts Mall · Php Scripts Mall Online Lottery Php Readymade Script
Aniket Dinda
·
Published
2019-03-29
·
Updated
2019-04-01
·
CVE-2019-9604
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHP Scripts Mall Online Lottery PHP Readymade Script version 1.7.0
Description
The issue concerns a Cross-Site Request Forgery (CSRF) flaw related to Edit Profile actions.
Recommendations
For PHP Scripts Mall Online Lottery PHP Readymade Script version 1.7.0, consider implementing proper CSRF token validation for the Edit Profile action to prevent unauthorized changes.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Scripts Mall Online Lottery Php Readymade Script