Description
ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credentials by submitting forged requests to _configurar_perfil.php. Attackers can craft malicious forms or links containing parameters like usuario, contrasena1, contrasena2, nombre, and email to change admin account settings without authentication.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Ihsan Sencan
References
www.exploit-db.com/exploits/45836 (ExploitDB-45836)
www.vulncheck.com/...equest-forgery-via-configurar-perfilphp (VulnCheck Advisory: ABC ERP 0.6.4 Cross-Site Request Forgery via _configurar_perfil.php)