إرسال #600581: CodeAstro Expense Management System 1.0 Cross-Site Request Forgeryالمعلومات

عنوانCodeAstro Expense Management System 1.0 Cross-Site Request Forgery
الوصفThe attacker can remotely craft a malicious link (using the CSRF vulnerability) and trick an authenticated user into clicking it. This allows the attacker to perform unauthorized actions, such as adding an expense entry, on behalf of the victim without their consent. Additionally, the attacker can insert malicious JavaScript into the value of an item in the "Add Expense" form. This malicious payload is sent via the CSRF request and stored in the system. The payload is then displayed in the Manage Expenses section. When the victim later visits the Manage Expenses page, the stored malicious JavaScript is executed, potentially leading to the theft of session cookies which leads to account takeover.
المصدر⚠️ http://codeastro.com
المستخدم
 yousufnihal (UID 76343)
ارسال19/06/2025 12:03 PM (8 أشهر منذ)
الاعتدال21/06/2025 07:43 AM (2 days later)
الحالةتمت الموافقة
إدخال VulDB313586 [CodeAstro Expense Management System 1.0 تزوير طلبات عبر المواقع]
النقاط17

Do you want to use VulDB in your project?

Use the official API to access entries easily!