School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/150009/School-Attendance-Monitoring-System-1.0-Shell-Upload.html | exploit vdb entry third party advisory |
https://www.exploit-db.com/exploits/45726/ | exploit vdb entry third party advisory |