Exploit/Advisories

Published on April 30th, 2020 📆 | 3999 Views ⚑

0

Complaint Management System 4.2 – Cross-Site Request Forgery (Delete User)


https://www.ispeech.org/text.to.speech

# Exploit Title: Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
# Author: Besim ALTINOK
# Vendor Homepage: https://phpgurukul.com/
# Software Link: https://phpgurukul.com/complaint-management-sytem/
# Version: v4.2
# Tested on: Xampp
# Credit: İsmail BOZKURT
*************************************************
Detail:

You can perform CSRF Attack for all the functions.

----------------------------------------------

CSRF PoC for Delete User
----------------------------------------------
This request performs over the GET request with uid.
------------------------------------------------------------------------





Source link

Tagged with:



Comments are closed.