PT-2020-13093 · Ismartgate · Ismartgate Pro

Published

2020-09-24

·

Updated

2020-09-27

·

CVE-2020-12282

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iSmartgate PRO version 1.5.9
Description The issue concerns a CSRF vulnerability that can be exploited via the busca parameter in the form used for searching for users, accessible through the "/index.php" API endpoint. This vulnerability can be combined with reflected XSS.
Recommendations For iSmartgate PRO version 1.5.9, consider implementing proper CSRF protection mechanisms, such as token-based validation, to prevent exploitation. As a temporary workaround, restrict access to the "/index.php" endpoint to minimize the risk of exploitation. Avoid using the busca parameter in the affected form until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12282

Affected Products

Ismartgate Pro