Skip to content

simple-cms has Cross-site request forgery #4

@SunJ3t

Description

@SunJ3t

http://192.168.2.129/simple/admin/?delpage=8

I can delete any page when I send the url to administrator.
I can also use the Short DomainNames to encode the url.

1

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions