You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jan 9, 2024. It is now read-only.
[Suggested description]
Cross Site Request Forgery (CSRF) vulnerability exists in KindEdirot
4.1.x. First, you upload an html file containing csrf on the website
that uses a google editor, (you only need to search in google:
inurl:/examples/uploadbutton.html) and then use the authority of this
website to trick users into clicking your malicious html link.
[Vulnerability Type]
Cross Site Request Forgery (CSRF)
[Affected Component]
To find a website that uses this editor, you only need to search in google: inurl:/examples/uploadbutton.html
Because this is the feature file of this editor
[Attack Type]
Remote
[Impact Code execution]
true
Attackers can use websites trusted by users to perform dangerous operations
[Attack Vectors]
<title>csrf test</title>
// your target url
The text was updated successfully, but these errors were encountered:
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
The text was updated successfully, but these errors were encountered: