PT-2020-16490 · Forma Spa · Forma Lms
Published
2020-10-08
·
Updated
2020-10-15
·
CVE-2020-26802
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
forma.lms version 2.3.0.2
Description
The issue allows for Cross Site Request Forgery (CSRF) in the "forma.lms" application, specifically in the "formalms/appCore/index.php" endpoint, when a GET request is made to "/index.php?r=lms/profile/show&ap=saveinfo". This can be exploited to change the admin email address, potentially leading to an account takeover.
Recommendations
For forma.lms version 2.3.0.2, as a temporary workaround, consider restricting access to the "/index.php?r=lms/profile/show&ap=saveinfo" endpoint to minimize the risk of exploitation. Avoid using the
ap and r parameters in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forma Lms