CSRF Vulnerability in Hashtopus 1.5g via admin.php Password Parameter

CSRF Vulnerability in Hashtopus 1.5g via admin.php Password Parameter

CVE-2017-11679 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action.

Learn more about our Web Application Penetration Testing UK.