Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php.
References
Link | Resource |
---|---|
https://github.com/s3inlc/hashtopussy/issues/241 | Exploit Third Party Advisory |
Configurations
Information
Published : 2017-07-26 23:29
Updated : 2017-08-02 08:47
NVD link : CVE-2017-11680
Mitre link : CVE-2017-11680
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
project_hashtopussy
- hashtopussy