Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-23824

Description

ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will run the CSRF.

POC

Reference

- https://github.com/V1n1v131r4/CSRF-on-ArGoSoft-Mail-Server/blob/master/README.md

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/404notf0und/CVE-Flow

- https://github.com/V1n1v131r4/My-CVEs

- https://github.com/cyb3r-w0lf/nuclei-template-collection