CSRF Vulnerability in RSVP Invitation Online 1.0 Allows Unauthorized Password Modification

CSRF Vulnerability in RSVP Invitation Online 1.0 Allows Unauthorized Password Modification

CVE-2018-5976 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password.

Learn more about our Web Application Penetration Testing UK.