WHMCS Multiple Security Vulnerabilities
BID:61279
Info
WHMCS Multiple Security Vulnerabilities
| Bugtraq ID: | 61279 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2013 12:00AM |
| Updated: | Mar 12 2013 12:00AM |
| Credit: | Vlad C. of NetSec Interactive Solutions |
| Vulnerable: |
WHMCS WHMCS 5.2 WHMCS WHMCS 5.1.3 WHMCS WHMCS 5.1.2 WHMCS WHMCS 5.0.3 WHMCS WHMCS 5.0.2 WHMCS WHMCS 4.5.3 WHMCS WHMCS 4.5.2 WHMCS WHMCS 4.4.2 WHMCS WHMCS 4.3.1 WHMCS WHMCS 4.2.1 WHMCS WHMCS 4.1.2 WHMCS WHMCS 4.0.1 WHMCS WHMCS 5.1 WHMCS WHMCS 5.0 WHMCS WHMCS 4.2 |
| Not Vulnerable: |
WHMCS WHMCS 5.2.1 WHMCS WHMCS 5.1.4 WHMCS WHMCS 5.0.4 |
Discussion
WHMCS Multiple Security Vulnerabilities
WHMCS is prone to multiple security vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to disclose sensitive information, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and perform unauthorized actions. Other attacks may also be possible.
WHMCS versions 4.x.x and versions 5.x.x are vulnerable.
WHMCS is prone to multiple security vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to disclose sensitive information, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and perform unauthorized actions. Other attacks may also be possible.
WHMCS versions 4.x.x and versions 5.x.x are vulnerable.
Exploit / POC
WHMCS Multiple Security Vulnerabilities
An attacker can exploit these issues using a web browser. To exploit multiple cross-site scripting issues and a cross-site request forgery issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues using a web browser. To exploit multiple cross-site scripting issues and a cross-site request forgery issue, an attacker must entice an unsuspecting victim to follow a malicious URI.