Websites managed by MegaBIP in versions below 5.15 are...
High severity
Unreviewed
Published
Jan 10, 2025
to the GitHub Advisory Database
•
Updated Jan 10, 2025
Description
Published by the National Vulnerability Database
Jan 10, 2025
Published to the GitHub Advisory Database
Jan 10, 2025
Last updated
Jan 10, 2025
Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php?id=7,7,0" lacks protection mechanisms.
A user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If the victim is a logged in administrator, this could lead to creation of new accounts and granting of administrative permissions.
References