CVE-2020-23836
HIGHOSWAPP Warehouse Inventory System < 2020-08-10 - Cross-Site Request Forgery in edit_user.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-23836. PoCs published by boku.
AI-analyzed exploit summary This is a functional CSRF exploit targeting Warehouse Inventory System 1.0, allowing an attacker to change the admin password by tricking an authenticated admin into visiting a malicious page. The exploit uses a hidden HTML form to submit a POST request to the vulnerable endpoint.
Description
A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.
Exploits (1)
This is a functional CSRF exploit targeting Warehouse Inventory System 1.0, allowing an attacker to change the admin password by tricking an authenticated admin into visiting a malicious page. The exploit uses a hidden HTML form to submit a POST request to the vulnerable endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H