CVE-2020-37145
MEDIUMHRSALE 1.1.8 - Cross-Site Request Forgery via Employee Registration Form
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37145. PoCs published by Ismail Akıcı.
AI-analyzed exploit summary This is a CSRF PoC that demonstrates how an attacker can add an admin user to HRSALE v1.1.8 by tricking an authenticated user into submitting a malicious form. The exploit leverages a lack of proper CSRF token validation.
Description
HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.
Exploits (1)
This is a CSRF PoC that demonstrates how an attacker can add an admin user to HRSALE v1.1.8 by tricking an authenticated user into submitting a malicious form. The exploit leverages a lack of proper CSRF token validation.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N