Skip to content

CSRF EmpireCMS7.2 exist #2

@mamakrs

Description

@mamakrs

Download the simplified version of EmpireCMS7.2 utf-8 on the empire website.Local installation vulnerability rediscovered

Register two regular users in CMS
image
The logon user is test and the receiving user is 123456
image
Build your own CSRF request code by grabbing the packet for the request。The package I built sends a message to the test user
image
Clear cookies exit test user login 123456 user
Run our built CSRF to let 123456 users access it
click
image
Message sent successfully
image
Login test user to view, message sent successfully

image
Look at the source code does not do user authentication
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions