An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending private messages to users by luring an authenticated user to a web page that automatically submits a form on their behalf.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HBtiteam Xbtit
APPBtiteam≤ 2.5.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2018-15680CRITICAL9.8PL ✓ten sam produkt
BTITeam XBTIT: przechowywanie haseł jako niezasalowane skróty MD5
CVE-2018-15681CRITICAL9.8PL ✓ten sam produkt
BTITeam XBTIT: słabe hashowanie hasła w cookie umożliwia odzyskanie hasła
CVE-2021-45821HIGH8.8ten sam produkt
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.p...
CVE-2021-45822MEDIUM6.1ten sam produkt
A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /aja...
CVE-2018-17870MEDIUM6.1ten sam produkt
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable t...