server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
References
Link | Resource |
---|---|
https://github.com/CCCCCrash/POCs/tree/master/Web/showdoc/csrf | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-11-28 00:29
Updated : 2018-12-26 10:30
NVD link : CVE-2018-19621
Mitre link : CVE-2018-19621
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
showdoc
- showdoc