CVE-2017-7571
HIGHFaveo 1.9.3 - Cross-Site Request Forgery in Role Change Admin
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-7571. PoCs published by rungga_reksya.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Faveo Helpdesk 1.9.3, allowing an attacker to escalate an agent's privileges to admin by tricking them into submitting a malicious form. The PoC includes a simple HTML form that triggers the role change via a POST request.
Description
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Faveo Helpdesk 1.9.3, allowing an attacker to escalate an agent's privileges to admin by tricking them into submitting a malicious form. The PoC includes a simple HTML form that triggers the role change via a POST request.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H