关键信息 CVE: CVE-2023-43147 Vendor: PHPJabbers Vendor Homepage: https://www.phpjabbers.com/ Software Link: https://www.phpjabbers.com/limo-booking-software Version: 1.0 Tested on: Windows 10 Pro Impact: Add an attacker user with admin privileges Vulnerability: Cross-Site Request Forgery (CSRF) Proof of Concept (POC) 1. Make an HTML file with the following code and save as . 2. Example contents: 3. Send the file to the victim. 4. When the victim opens the HTML file, the script will automatically submit the form, adding a new admin user with the specified credentials.