Release date:
Updated on:
Affected Systems:
PlaySMS SMS Gateway 0.9.2
Description:
--------------------------------------------------------------------------------
Playsms is an open-source SMS management system.
PlaySMS SMS Gateway 0.9.2 and other versions do not correctly verify the user's HTTP request. There is a security vulnerability in implementation. After successful exploitation, attackers can change the administrator password.
<* Source: Saadat Ullah
Link: http://secunia.com/advisories/56038/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PlaySMS
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://playsms.sourceforge.net/
Http://security-geeks.blogspot.dk/2013/12/playsms-0992-csrf.html