Description
Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin user with full system privileges when a logged-in user visits the page.
Problem types
CWE-798: Use of Hard-coded Credentials
Product status
Model: iZero
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/49458 (ExploitDB-49458)
www.selea.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5618.php (Zero Science Lab Disclosure (ZSL-2021-5618))
github.com/zeroscience (GitHub Repository of Zero Science)
www.vulncheck.com/...site-request-forgery-via-admin-creation (VulnCheck Advisory: Selea Targa IP Camera Cross-Site Request Forgery via Admin Creation)