This is a writeup detailing a CSRF vulnerability in DubSite CMS v1.0, allowing an attacker to change the administrative password or create a new admin user via crafted URLs. No exploit code is provided, only proof-of-concept URLs.
Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:DubSite CMS v1.0
No auth needed
Prerequisites:Victim must be authenticated as an admin and tricked into clicking a malicious link