mooSocial v3.1.8 is vulnerable to Cross Site Request Forgery (CSRF) which allows attacker to change admin password.# CVE-2023-44811
mooSocial v3.1.8 is vulnerable to Cross Site Request Forgery (CSRF) which allows attacker to change admin password once an authenticated admin user clicks on the malicious crafted HTML page.
I am providing 2 HTML Pages which will when clicked by an authenticated admin user will change their password.
[4.0K] /data/pocs/e5b1b687fd268e4e8e8521362a08d97f48dbbb23
├── [ 589] poc-click.html
├── [ 635] poc-non-interactive.html
└── [ 320] README.md
0 directories, 3 files