Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-33409: GitHub - Thirukrishnan/CVE-2023-33409

Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.

CVE
#csrf#git#php

CVE-2023-33409

Minical 1.0.0 is vulnerable to Cross-Site Request Forgery.

Vendor: https://github.com/minical/minical

Demo Application: https://demo.minical.io/

PoC

The application does not have any CSRF protection, hence a specially crafted HTTP request can be used to,

  • Add New User
  • Delete Existing User
  • Edit the existing User’s Email Address and other sensitive information.

The payloads for different attacks can be generated using the Generate CSRF POC tool in BurpSuite.

Example:

Add New User:

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907