Admidio 是一个开源的用户管理解决方案。在 5.0.11 及更早版本中,modules/plugins.php 端点通过 GET 请求处理插件的安装、卸载和更新操作,且未进行 CSRF 令牌验证。由于这些操作属于顶级导航,浏览器会携带 SameSite=Lax 属性的会话 Cookie 发起请求。攻击者可构造一个恶意网页,当已认证的管理员访问该页面时,即可触发任意的插件操作。其中,卸载操作会执行 SQL 脚本,从而销毁插件数据。该问题已在提交 056b1bd 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet