wetech-cms icon indicating copy to clipboard operation
wetech-cms copied to clipboard

There is a CSRF vulnerability in adding an administrator user

Open unafraid-fearless opened this issue 8 months ago • 0 comments

1.Interface address location:http://{IP_address}/wetech_web/admin/user/add.do image image image

2.I deleted the Referer and Origin fields,Interface replay successful,Here Generate CSRF HTML using Burp,The username and password are designed to be root123 csrf1 csrf1 csrf1 3.Click on the fake link image image image

Successfully logged in using account root123

unafraid-fearless avatar Jun 05 '24 03:06 unafraid-fearless