mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 17:50:34 +00:00
20 lines
703 B
Markdown
20 lines
703 B
Markdown
![]() |
### [CVE-2017-7571](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7571)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- http://rungga.blogspot.co.id/2017/04/csrf-privilege-escalation-manipulation.html
|
||
|
- https://github.com/ladybirdweb/faveo-helpdesk/issues/446
|
||
|
- https://www.exploit-db.com/exploits/41830/
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
|