Description
PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests to the users.php endpoint with parameters like name, email, password, and permissions set to admin to create unauthorized admin accounts.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Alireza Norkazemi
References
www.exploit-db.com/exploits/45636 (ExploitDB-45636)
github.com/joeyrush/PHP-SHOP/archive/master.zip (Product Reference)
www.vulncheck.com/...ross-site-request-forgery-via-users-php (VulnCheck Advisory: PHP-SHOP 1.0 Cross-Site Request Forgery via users.php)