CSRF in Qloapps HotelCommerce 1.5.1# CVE-2021-41074
CSRF in Qloapps HotelCommerce 1.5.1
There is a CSRF in HotelCommerce 1.5.1. It can allow anyone to change the admin email.
If an attacker gets an admin to click a maliciously crafted html document, they can change the admin user email.
[4.0K] /data/pocs/c4a04860c111b31a183b98b21cd67f3dbde5d553
├── [1.0K] LICENSE
├── [1.4K] POC.html
├── [ 256] README.md
└── [1.4K] zero_click_POC.html
0 directories, 4 files