| Kura | CodeAstro Expense Management System 1.0 Cross-Site Request Forgery |
|---|
| Gaskiya | The attacker can remotely craft a malicious link (using the CSRF vulnerability) and trick an authenticated user into clicking it. This allows the attacker to perform unauthorized actions, such as adding an expense entry, on behalf of the victim without their consent.
Additionally, the attacker can insert malicious JavaScript into the value of an item in the "Add Expense" form. This malicious payload is sent via the CSRF request and stored in the system. The payload is then displayed in the Manage Expenses section. When the victim later visits the Manage Expenses page, the stored malicious JavaScript is executed, potentially leading to the theft of session cookies which leads to account takeover. |
|---|
| Manga | ⚠️ http://codeastro.com |
|---|
| Màdùmga | yousufnihal (UID 76343) |
|---|
| Furta | 06/19/2025 12:03 (8 Wurɗi 전) |
|---|
| Gargajiya | 06/21/2025 07:43 (2 days later) |
|---|
| Halitta | Shingilam |
|---|
| VulDB gite | 313586 [CodeAstro Expense Management System 1.0 Kari ndiyam site laa request forgery] |
|---|
| Nganji | 17 |
|---|