This exploit demonstrates multiple vulnerabilities in kilrizzy-Nakid-CMS-f274624, including CSRF, persistent XSS, and LFI. It provides PoC code for adding arbitrary users, changing admin passwords, altering system settings, and bypassing authentication via LFI.
Classification
Working Poc 95%
Attack Type
Xss | Auth Bypass | Info Leak
Target:
kilrizzy-Nakid-CMS-f274624
No auth needed
Prerequisites:
Victim must have an active session for CSRF attacks · Access to the target web application