PT-2019-9633 · Tubigan · Tubigan

Published

2019-06-18

·

Updated

2019-06-18

·

CVE-2018-18802

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tubigan "Welcome to our Resort" version 1.0
Description The issue allows for CSRF, which can be exploited via the "admin/mod users/controller.php?action=edit" API endpoint. This could potentially allow attackers to perform unauthorized actions on the application.
Recommendations For version 1.0, consider implementing proper CSRF protection mechanisms, such as token-based validation, to prevent unauthorized requests to the "admin/mod users/controller.php?action=edit" endpoint. As a temporary workaround, restrict access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18802

Affected Products

Tubigan