Exploits / Vulnerability Discovered : 2018-04-24 |
Type : webapps |
Platform : php
This exploit / vulnerability Wuzhi cms 4.1.0 crosssite request forgery is for educational purposes only and if it is used you will do on your own risk!
An issue was discovered in WUZHI CMS 4.1.0 (https://github.com/wuzhicms/wuzhicms/issues/132)
There is a csrf vulnerability that can modifying the member's password. via index.php?m=member&v=pw_reset
After the member logged in. open the exp page