Skip to content

ModStartCMS V4.6.0 has a vulnerability, Cross-site request forgery(CSRF) #3

@Rookie-is

Description

@Rookie-is

Build ModStartCMSv4.6.0 locally
Background, background permissions -> administrator -> add
image
Click to add a user test
image
packet capture
image
send csrf poc
image
image
image
Click to send,refresh background
image
image
New administrator test appears

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions