A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://phpmywind.com | broken link |
https://github.com/gaozhifeng/PHPMyWind | third party advisory product |
https://github.com/gaozhifeng/PHPMyWind/issues/9 | third party advisory exploit |