There is a cross-site request forgery vulnerability in admin.php?mod=users
It and can change administrator's password.
First:
After the administrator logged in,open the poc page.
Aura.txt to Aura.html --> change administrator's password.
Second:
Check the results after modifying the password.
Success!
CSRF POC:
Aura.txt
There is a cross-site request forgery vulnerability in admin.php?mod=users It and can change administrator's password. First: After the administrator logged in,open the poc page. Aura.txt to Aura.html --> change administrator's password. Second: Check the results after modifying the password. Success! CSRF POC: Aura.txt