6.8
CVSSv2

CVE-2018-7176

Published: 16/02/2018 Updated: 14/03/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).

Vulnerable Product Search on Vulmon Subscribe to Product

frontaccounting frontaccounting 2.4.3

Exploits

<!-- ​​# Exploit Title: Front Accounting ERP 243 - CSRF # Date: 16-02-2018 # Exploit Author: Samrat Das # Contact: twittercom/Samrat_Das93 # Website: securitywarrior9blogspotin/ # Vendor Homepage: frontaccountingcom # Version: 243 # CVE : CVE-2018-7176 # Category: WebApp ERP 1 Description The application source code ...
Front Accounting ERP version 243 suffers from a cross site request forgery vulnerability ...