Companys recruitment management system 1.0 add new user crosssite request forgery (csrf) Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2021-10-18 |
Type : webapps |
Platform : php
This exploit / vulnerability Companys recruitment management system 1.0 add new user crosssite request forgery (csrf) is for educational purposes only and if it is used you will do on your own risk!
Detail:
The application is not using any security token to prevent it against CSRF. Therefore, malicious user can add new administrator user account by using a crafted post request.