8.8
CVSSv3

CVE-2018-11445

Published: 25/05/2018 Updated: 02/07/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A CSRF issue exists on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.

Vulnerable Product Search on Vulmon Subscribe to Product

easyservice billing project easyservice billing 1.0

Exploits

<!-- # Exploit Title: EasyService Billing 10 Multiple Cross-Site Request Forgery # Date: 25-05-2018 # Software Link: codecanyonnet/item/easyservice-billing-php-scripts-for-quotation-invoice-payments-etc/16687594 # Exploit Author: Divya Jain # Version: EasyService Billing 10 # CVE: CVE-2018-11445,CVE-2018-11442 # Category: Webapps # ...
EasyService Billing version 10 suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities ...