关键信息 EDB-ID: 48141 CVE: N/A Author: MEISAM MONSEF Type: WEBAPPS Platform: PHP Date: 2020-02-27 Exploit Title: Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin) Description: Operator Can Change Role User Type to admin Exploit Author: Meisam Monsef Vendor Homepage: https://www.bdtask.com/business-live-chat-software.php Version: V-1.0 Tested on: Ubuntu 漏洞利用步骤 1. 请登录或创建账户 2. 在浏览器中打开exploit.html 3. 将user id输入项的用户类型更改为admin 4. 填写输入数据(fname - lname - email) 5. 单击“添加”按钮 漏洞代码片段