Description
Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative accounts without the victim's consent.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Extinction
References
www.exploit-db.com/exploits/48571 (ExploitDB-48571)
adikiss.net/ (Vendor Homepage)
adikiss.net/...stem-informasi-pengumuman-kelulusan-online-2/ (Software Download Page)
www.vulncheck.com/...lusan-online-cross-site-request-forgery (VulnCheck Advisory: Sistem Informasi Pengumuman Kelulusan Online 1.0 - Cross-Site Request Forgery)