# Exploit Title: HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin) # Date: 2020-03-11 # Exploit Author: Ismail Akıcı # Vendor Homepage: http://hrsale.com/ # Software Link : http://demo.hrsale.com/ # Software : HRSALE v1.1.8 # Product Version: v1.1.8 # Vulnerability Type : Cross-Site Request Forgery (Add Admin) # Vulnerability : Cross-Site Request Forgery # Description : # CSRF vulnerability was discovered in v1.1.8 version of HRSALE. # With this vulnerability, authorized users can be added to the system. HTML CSRF PoC :