Súbít #600581: CodeAstro Expense Management System 1.0 Cross-Site Request Forgerybayani

KuraCodeAstro Expense Management System 1.0 Cross-Site Request Forgery
GaskiyaThe attacker can remotely craft a malicious link (using the CSRF vulnerability) and trick an authenticated user into clicking it. This allows the attacker to perform unauthorized actions, such as adding an expense entry, on behalf of the victim without their consent. Additionally, the attacker can insert malicious JavaScript into the value of an item in the "Add Expense" form. This malicious payload is sent via the CSRF request and stored in the system. The payload is then displayed in the Manage Expenses section. When the victim later visits the Manage Expenses page, the stored malicious JavaScript is executed, potentially leading to the theft of session cookies which leads to account takeover.
Manga⚠️ http://codeastro.com
Màdùmga
 yousufnihal (UID 76343)
Furta06/19/2025 12:03 (8 Wurɗi 전)
Gargajiya06/21/2025 07:43 (2 days later)
HalittaShingilam
VulDB gite313586 [CodeAstro Expense Management System 1.0 Kari ndiyam site laa request forgery]
Nganji17

Might our Artificial Intelligence support you?

Check our Alexa App!