Yoga Class Registration System 1.0 - ATO
6,5
Medium
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Yoga Class Registration System 1.0 - RCE
Code name
State
Public
Release date
23 jun 2023
Affected product
Yoga Class Registration System
Affected version(s)
Version 1.0
Vulnerability name
Cross-site request forgery
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v3.1 base score
6.5
Exploit available
Yes
CVE ID(s)
Description
Yoga Class Registration System Version 1.0 allows an external attacker to elevate privileges in the application. This is possible because the application is not protected against CSRF attacks.
Vulnerability
The application is not protected against CSRF attacks, so an attacker can persuade an administrator to create a new account with administrative permissions, along with the credentials set by the attacker.
Exploitation
To exploit the vulnerability I have written the following exploit:
Evidence of exploitation


Our security policy
We have reserved the CVE-2023-1722 to refer to these issues from now on. Disclosure policy
System Information
Version: OrangeScrum 2.0.11
Operating System: GNU/Linux
Mitigation
There is currently no patch available for this vulnerability.
References
Timeline
IA generativa
31 mar 2023
Vendor contacted
31 mar 2023
Vendor replied
31 mar 2023
Public disclosure
13 jun 2023