Description
Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Metin Yunus Kandemir
References
www.exploit-db.com/exploits/48234 (ExploitDB-48234)
www.exagate.com/ (Exagate Vendor Homepage)
web.archive.org/...936/https://www.exagate.com/sysguard-6001 (Archived Sysguard 6001 Product Page)
www.vulncheck.com/...rd-cross-site-request-forgery-add-admin (VulnCheck Advisory: Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin))