A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.andmp.com/2018/02/advisory-assigned-cve-2018-7308-csrf.html | third party advisory |
https://github.com/DanWin/hosting/issues/18 | third party advisory |