Cross-Site Request Forgery in Employee Timeclock Software by Unknown Vendor
CVE-2010-0707

Currently unrated

Key Information:

Vendor
CVE Published:
25 February 2010

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2010-0707?

A cross-site request forgery (CSRF) vulnerability exists in the add_user.php script of Employee Timeclock Software version 0.99. This flaw enables remote attackers to trick an authenticated administrator into executing unauthorized actions. Specifically, attackers can create new administrative users by hijacking the existing session, which poses a significant risk to the integrity of the application. It is crucial for users of this software to implement appropriate security measures to mitigate the risk associated with this vulnerability.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.