Executive brief
Zechat is a PHP-based chat application. A security flaw in version 1.5 allows an attacker to trick a logged-in user into unknowingly performing actions, such as changing their account profile information or email address. This could lead to unauthorized account modifications or potential account takeover if a user visits a malicious website while logged into the chat service.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Zechat 1.5 due to insufficient protection on sensitive user-data update endpoints. While the application implements a CSRF token mechanism, it is vulnerable to a bypass. An attacker can leverage a reflected XSS vulnerability in the 'hashtag' parameter or use a script to programmatically fetch the valid CSRF token from the settings page and then submit a forged POST request to /chat/data_settings.php. This allows an unauthenticated remote attacker to modify user profile details, including names and email addresses, provided they can trick an authenticated user into interacting with a malicious link or form. Proof-of-concept exploits also indicate related SQL injection vulnerabilities in the 'hashtag' and 'v' parameters.
Affected products
- Bylancer Zechat 1.5
Timeline
- 2018-05-22: disclosed: Original exploit and vulnerability details published on Exploit-DB
- 2026-05-17: advisory: CVE-2018-25334 published to NVD via VulnCheck enrichment