CSRF Vulnerability in Sentrifugo 3.2 Allows Arbitrary Code Execution

CSRF Vulnerability in Sentrifugo 3.2 Allows Arbitrary Code Execution

CVE-2019-16059 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page.

Learn more about our Web Application Penetration Testing UK.