# Exploit Title: PowerPanel Business Edition 3.4.0 - Cross Site Request Forgery # Date: 7/9/2019 # Exploit Author: Joey Lane # Vendor Homepage: https://www.cyberpowersystems.com # Version: 3.4.0 # Tested on: Ubuntu 16.04 # CVE : CVE-2019-13071 # Reported to vendor on 5/25/2019, no acknowledgement. The Agent/Center component of PowerPanel Business Edition is vulnerable to cross site request forgery. This can be exploited by tricking an authenticated user into visiting a web page controlled by a malicious person. The following example uses CSRF to disable Status Recording under the Logs / Settings page. Create a file named 'csrf.html' on a local workstation with the following contents:
Serve the file using python or any other web server: python -m SimpleHTTPServer 8000 Visit the local page in a browser while logged into PowerPanel Business Edition: http://localhost:8000/csrf.html The hidden form is submitted in the background, and will disable Status Recording. This could be adapted to exploit other forms in the web application as well.