Lucene search

K
huntrKtg963F24B24-4AF2-47B8-BAEA-7AD5F4DB3633
HistoryJan 12, 2022 - 6:30 a.m.

Cross-Site Request Forgery (CSRF) in phoronix-test-suite/phoronix-test-suite

2022-01-1206:30:14
ktg9
www.huntr.dev
10
cross-site request forgery
phoronix
benchmarking

EPSS

0.001

Percentile

46.6%

Description

Hi there, I would like to report another CSRF in phoronix

Proof of Concept

  1. Install a local instance of phoronix
  2. Create a benchmark and note down benchmark id
  3. Access the link /?benchmark/<benchmark-id>/&repeat, /?benchmark/<benchmark-id>/&disable and /?benchmark/<benchmark-id>/&remove and see that the benchmark is repeated, disabled and removed.

Impact

This vulnerability is capable of CSRF.

EPSS

0.001

Percentile

46.6%

Related for 63F24B24-4AF2-47B8-BAEA-7AD5F4DB3633