This exploit demonstrates a privilege escalation vulnerability in Monstra CMS 3.0.3, allowing any authenticated user to change the password of other users, including the administrator, by manipulating POST parameters. It also includes a persistent XSS vulnerability in the 'Edit Profile' page.
Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:Monstra CMS 3.0.3
Auth required
Prerequisites:Authenticated user access · Knowledge of target user IDs