# Exploit Title: Vesta Control Panel CSRF(change admin password) # Date: 24-05-2015 # Exploit Author: Ben Khlifa Fahmi # Vendor Homepage: https://vestacp.com/ # Software Link: http://vestacp.com/pub/vst-install.sh # Version: 0.9.8(amd64) # Tested on: ubuntu trusty 14.04 Description: --------------------------------------------------------------- The vulnerability exist on the page /edit/user/index.php The VESTA CP is vulnerable to CSRF Where an attacker can change "admin" password by sending to already logged in user , once the victim visit the page the user password will changed to the one has been set by attacker. Exploit Code :