A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/?page=contact_us of the component Contact Us. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-211194 is the identifier assigned to this vulnerability.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/souravkr529/CSRF-in-Cold-Storage-Management-System/blob/main/PoC | third party advisory exploit |
https://vuldb.com/?id.211194 | third party advisory |