Description
Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authentication. Attackers can craft a malicious HTML form to modify user privileges by submitting a POST request to the user creation endpoint with administrative access parameters.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Meisam Monsef
References
www.exploit-db.com/exploits/48141 (ExploitDB-48141)
www.bdtask.com/business-live-chat-software.php (Business Live Chat Software Vendor Homepage)
www.vulncheck.com/...re-cross-site-request-forgery-add-admin (VulnCheck Advisory: Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin))