Description
Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to register new users with arbitrary credentials and escalate privileges to SUPERUSER level.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
References
www.exploit-db.com/exploits/38496 (ExploitDB-38496)
www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5269.php (Zero Science Lab Disclosure)
www.vulncheck.com/...uest-forgery-unauthorized-user-creation (VulnCheck Advisory: RealtyScript 4.0.2 Cross-Site Request Forgery Unauthorized User Creation)