A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://detapos.co/ | third party advisory |
https://demo.detapos.co.id/petshop/ | third party advisory permissions required |
http://rysec.io/adv/Petshop_AddAdmin_Exploit.txt | url repurposed third party advisory exploit |
http://packetstormsecurity.com/files/159520/Garfield-Petshop-2020-10-01-Cross-Site-Request-Forgery.html | third party advisory |