Pentest Tools

Published on February 24th, 2020 📆 | 4048 Views ⚑

0

CandidATS 2.1.0 Cross Site Request Forgery


iSpeech.org

# Title: CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
# Date: 2020-02-21
# Exploit Author: J3rryBl4nks
# Vendor Homepage: https://sourceforge.net/u/auieo/profile/
# Software Link: https://sourceforge.net/projects/candidats/files/#Version 2.1.0
# Tested on Ubuntu 19/Kali Rolling

# The Candid ATS Web application is vulnerable to CSRF to add a new admin user:
#CSRF Proof of Concept:




















Source link





Tagged with:



Comments are closed.