CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://0day4u.wordpress.com/2018/03/12/97/ | third party advisory exploit |