This exploit demonstrates a CSRF vulnerability to add an admin user and a persistent XSS vulnerability in Ushahidi 2.2. The CSRF PoC submits a form to create an admin user without user interaction, while the XSS PoC involves injecting malicious script via the username field during user creation.
Classification
Working Poc 90%
Attack Type
Xss | Auth Bypass
Target:
Ushahidi 2.2
No auth needed
Prerequisites:
Victim must visit a malicious page for CSRF · Admin must view the users page for XSS