Skip to content

There is a CSRF vulnerability that can add administrator. #1

@FuryKangaroo

Description

@FuryKangaroo

After the administrator logged in,open the poc page.
copy add.txt to add.html and let the administrator open the add.html
vulnerability location:/EmpireCMS-master/upload/e/admin/user/AddUser.php?enews=AddUser

Before modification

default
default

After modification
default

Payload location:
add.txt

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions