noumo / easyii

Easy yii2 cms powered by Yii framework 2
http://easyiicms.com
593 stars 272 forks source link

CSRF in Logout #222

Open white8086 opened 4 years ago

white8086 commented 4 years ago

Hi can force logout any user with this form

vulnerable endpoint: http://example.com/admin/sign/out