Description
iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF protections.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
5.6 B2017.07.12.1757
4.3
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/48990
www.exploit-db.com/exploits/48990 (ExploitDB-48990)
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5606.php (Zero Science Lab Disclosure (ZSL-2020-5606))
web.archive.org/web/20200919100215/http://www.yerootech.com/ (Archived Yeroo Tech Vendor Homepage)
packetstormsecurity.com/files/159916 (Packet Storm Security Exploit Entry)
exchange.xforce.ibmcloud.com/vulnerabilities/191258 (IBM X-Force Vulnerability Exchange)
cxsecurity.com/issue/WLB-2020110022 (CXSecurity Vulnerability Database Entry)
www.vulncheck.com/...ite-request-forgery-via-user-management (VulnCheck Advisory: iDS6 DSSPro Digital Signage System 6.2 Cross-Site Request Forgery via User Management)