FrontAccounting 2.4.20 及更早版本在 的 函数中生成 CSRF token,并将其作为 隐藏字段嵌入到其渲染的每个表单中。然而,只有 和 调用了 对该 token 进行校验。其他处理财务交易的端点均未校验该 token,包括: 因此,这些端点在处理 POST 数据时未进行来源检查。攻击者若能让已认证用户访问攻击者控制的页面,即可自动提交跨域表单,从而以受害者的会话身份记录伪造的日记账分录、发票、客户付款、银行交易或公司配置变更。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FrontAccounting | FrontAccounting | 0 ~ 2.4.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet