BOOK THIS SPACE FOR AD
ARTICLE AD# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.LockDocument.php
# Date: 02/08/21
# Exploit Author: Division of Cyber Security & Digital Forensics — VIT Bhopal University
# Vendor Homepage: https://www.seeddms.org/
# Version: 5.1.x<5.1.23 and 6.0.x<6.0.16
# CVE : CVE-2021–35343
Description:
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to lock any document without victim’s knowledge, by enticing an authenticated user to visit an attacker’s web page.
Steps to reproduce:
1. Login with the admin account.
2. Visit this URL: http://localhost/op/op.LockDocument.php?documentid=<ID>
You’ll see that the document will be locked.