WXiangQian / wage-cms

💡基于laravel-admin1.5开发的工资管理系统,含excel导出、查询快递功能
66 stars 36 forks source link

CSRF in /admin/users #1

Open jinnywc opened 4 years ago

jinnywc commented 4 years ago

Version 1.5.x-dev CSRF vulnerability in employee management Before CSRF csrf1 Click 'Add' and edit employee information csrf2 Grab the packet and construct the payload of CSRF, and save it as csrf.html csrf3 Visit csrf.html and click 'submit request' csrf4 Employee added successfully csrf5

WXiangQian commented 4 years ago

1.5.x可能是框架的弊端,本项目学习入门专用,可选择使用laravel-admin最新版本学习