TomatoCart Anti-CSRF Token Security Bypass Vulnerability
BID:57167
Info
TomatoCart Anti-CSRF Token Security Bypass Vulnerability
| Bugtraq ID: | 57167 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2013 12:00AM |
| Updated: | Jan 07 2013 12:00AM |
| Credit: | Aung Khant |
| Vulnerable: |
TomatoCart TomatoCart 1.1 |
| Not Vulnerable: | |
Discussion
TomatoCart Anti-CSRF Token Security Bypass Vulnerability
TomatoCart is prone to a security-bypass vulnerability because of a design error in the implementation of the anti-CSRF token security feature.
An attacker may exploit this issue to bypass the anti-CSRF token security protections and perform cross-site request forgery attacks to perform unauthorized actions in the context of a victim's session. This may aid in other attacks.
TomatoCart is prone to a security-bypass vulnerability because of a design error in the implementation of the anti-CSRF token security feature.
An attacker may exploit this issue to bypass the anti-CSRF token security protections and perform cross-site request forgery attacks to perform unauthorized actions in the context of a victim's session. This may aid in other attacks.
Exploit / POC
TomatoCart Anti-CSRF Token Security Bypass Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
TomatoCart Anti-CSRF Token Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
TomatoCart Anti-CSRF Token Security Bypass Vulnerability
References:
References:
- TomatoCart 1.x | Cross Site Request Forgery Protection Bypass via JavaScript Hij (Aung Khant)
- TomatoCart Homepage (TomatoCart)