xwlrbh / Catfish

Catfish CMS
Other
8 stars 1 forks source link

Bug: CatfishCMS V 4.8.63 CSRF #5

Open GodEpic opened 5 years ago

GodEpic commented 5 years ago

Hi, I would like to report CSRF vulnerability in CatfishCMS V 4.8.63. There is a CSRF vulnerability that can be get administrator permissions. POC: 1.Login to administrator panel. 2.Open below URL in browser which supports flash. url:http://www.catfish.com/index.php/admin/Index/manageuser.html eg: 1.Before modification csrf1

2.CSRF POC csrf.txt

3.After modification csrf2

fix: Sensitive operations add token validation.

xwlrbh commented 5 years ago

thanks