# Exploit Title: [Cobub Razor 0.7.2 Cross Site Request Forgery] # Date: [2018-03-07] # Exploit Author: [ppbi1/4ppb@5ecurity.cni1/4] # Vendor Homepage: [https://github.com/cobub/razor/] # Software Link: [https://github.com/cobub/razor/] # Version: [0.72] # CVE : [CVE-2018-7746] There is a vulnerability. Authentication is not required for /index.php?/manage/channel/modifychannel. For example, with a crafted channel name, stored XSS is triggered during a later /index.php?/manage/channel request by an admin.