Information
--------------------
Advisory by Netsparker
Name: Cross-site Request Forgery Vulnerabilities in Serenity 3.0.5
Affected Software: Serenity
Affected Versions: 3.0.5
Homepage: http://serenity.is/
Vulnerability: Cross-site Request Forgery Vulnerability
Severity: Low
Status: Not Fixed
CVE-ID: 2018-14489
CVSS Score (3.0): CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Netsparker Advisory Reference: NS-18-017

Technical Details
--------------------

CSRF

Url : http://serenedemo.azurewebsites.net/services/Administration/User/Create
Note: Attacker can add new User. Attacker need to set Content-type:application/json for exploit it. (Content-type could be set with SWF files ie: https://github.com/sp1d3r/swf_json_csrf/)

CSRF

Url: http://serenedemo.azurewebsites.net/services/Administration/User/Update
Note: Attacker can change password any user. Attacker need to set Content-type:application/json for exploit it. (Content-type could be set with SWF files ie: https://github.com/sp1d3r/swf_json_csrf/)

For more information on Cross-Site Request Forgery vulnerabilities read the article Cross-Site Request Forgery.

Advisory Timeline
--------------------

16th October 2017 - First Contact Attempt 
29th November 2018 - Advisory Released

Credits & Authors
--------------------

These issues have been discovered by Mustafa Yalçın while testing Netsparker Web Application Security Scanner.

About Netsparker
--------------------

Netsparker web application security scanners find and report security flaws and vulnerabilities such as SQL Injection and Cross-site Scripting (XSS) in all websites and web applications, regardless of the platform and technology they are built on. Netsparker scanning engine’s unique detection and exploitation techniques allow it to be dead accurate in reporting vulnerabilities. The Netsparker web application security scanner is available in two editions; Netsparker Desktop and Netsparker Cloud. Visit our website https://www.netsparker.com for more information.