8.8
CVSSv3

CVE-2018-11442

Published: 25/05/2018 Updated: 02/07/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A CSRF issue exists in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.

Vulnerable Product Search on Vulmon Subscribe to Product

easyservice billing project easyservice billing 1.0

Exploits

<!-- # Exploit Title: EasyService Billing 10 Multiple Cross-Site Request Forgery # Date: 25-05-2018 # Software Link: codecanyonnet/item/easyservice-billing-php-scripts-for-quotation-invoice-payments-etc/16687594 # Exploit Author: Divya Jain # Version: EasyService Billing 10 # CVE: CVE-2018-11445,CVE-2018-11442 # Category: Webapps # ...
EasyService Billing version 10 suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities ...