CVE-2018-6563
HIGHtotemo encryption_gateway < 6.0.0 - Cross-Site Request Forgery
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-6563. PoCs published by Compass Security.
AI-analyzed exploit summary This is a working proof-of-concept for a CSRF vulnerability in totemomail Encryption Gateway. It demonstrates how an attacker can craft a malicious web page to execute unauthorized actions on behalf of a logged-in user by replaying a sequence of requests.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by leveraging lack of an anti-CSRF token.
Exploits (1)
This is a working proof-of-concept for a CSRF vulnerability in totemomail Encryption Gateway. It demonstrates how an attacker can craft a malicious web page to execute unauthorized actions on behalf of a logged-in user by replaying a sequence of requests.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H