目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-57373 PoC — Lifestyle Stores 安全漏洞

来源
关联漏洞
标题: Lifestyle Stores 安全漏洞 (CVE-2024-57373)
Description:Lifestyle Stores是Lifestyle Stores公司的一个在线购物网站。 Lifestyle Stores v.1.0版本存在安全漏洞,该漏洞源于存在跨站请求伪造漏洞,允许远程攻击者执行任意代码并获取敏感信息。
Description
 CSRF vulnerability in LifestyleStore v1.0, enabling unauthorized actions on behalf of users, risking data and account security
介绍
# CSRF Vulnerability in LifestyleStore v1.0  

## 📌 Overview  
This repository documents a **Cross-Site Request Forgery (CSRF)** vulnerability identified in the **LifestyleStore v1.0** project. The flaw allows attackers to perform unauthorized actions on behalf of authenticated users, posing risks to data integrity and account security.  

---

## 🛠️ Technical Details  
- **Type**: CSRF (Cross-Site Request Forgery)  
- **Impact**: Unauthorized actions such as data modification or account compromise.  
- **Affected Version**: LifestyleStore v1.0  
- **Severity**: High  

---

## 💡 How It Works  
1. The application does not validate the authenticity of requests.  
2. Attackers can trick users into executing unintended actions by embedding malicious links or forms in a third-party site.  
3. Once clicked, the actions are executed in the context of the victim's authenticated session.  

---

## 🔒 Steps to Mitigate  
To protect against CSRF vulnerabilities, implement:  
- **CSRF Tokens**: Add unique tokens to all forms and validate them on the server.  
- **SameSite Cookies**: Use `SameSite` attributes for cookies to prevent cross-origin requests.  
- **User Confirmation**: Require explicit user confirmation for sensitive actions.  


## ✍️ Author  
**David P.S. Abraham (Davycipher)**  
- 📧 Email: davycypher@gmail.com  
- 🌐 GitHub: [cypherdavy](https://github.com/cypherdavy)  
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →