Document Title: =============== Telecom Charging Panel ADSL (IR) - CSRF Web Vulnerability References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=1773 Release Date: ============= 2016-03-01 Vulnerability Laboratory ID (VL-ID): ==================================== 1773 Common Vulnerability Scoring System: ==================================== 3 Product & Service Introduction: =============================== Iran Telecom is a provider that offers ISP, telecommunication and hosting services to the private community and public industry. (Copy of the Vendor Homepage: http://www.tcg.ir/) Abstract Advisory Information: ============================== An independent vulnerability laboratory researcher discovered a client-side cross site request forgery vulnerability in the Iran Telecom Charging Panel ADSL. Vulnerability Disclosure Timeline: ================================== 2016-03-02: Public Disclosure (Vulnerability Laboratory) Discovery Status: ================= Published Exploitation Technique: ======================= Remote Severity Level: =============== Low Technical Details & Description: ================================ A client-side cross site scripting web vulnerability has been discovered in the official Iran Telecom Charging Panel ADSL. The vulnerability allows remote attacker to manipulate client-side web-application to browser requests to compromise session data. The vulnerability is located in the form1 of the vulnerable `customer.php` file POST method request. Remote attackers with low privileged web-application user accounts are able to inject own malicious script code to compromise client-side panel to browser requests. The request method to inject is POST and the attack vector is located on the client-side of the online-service. The security risk of the cross site vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 3.0. Exploitation of the cross site request forgery vulnerability requires no privileged web-application user account and medium user interaction. Successful exploitation results in client-side account theft by hijacking, client-side phishing, client-side external redirects and non-persistent manipulation of affected or connected service modules. Request Method(s): [+] POST Vulnerable File(s): [+] customer.php Vulnerable Parameter(s): [+] form1 Proof of Concept (PoC): ======================= The cross site request forgery vulnerability can be exploited by remote attackers without privileged web-application user account and with medium user interaction. For security demonstration or to reproduce the vulnerability follow the provided information and steps below to continue. PoC: Exploit (CSRF)