Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/polling-repo-continua/cve-2022-25257
Vulnerability AnalysisExploitationWeb Application ExploitationPhishingSocial Engineering
GitHubpolling-repo-continua/cve-2022-25257

CVE-2022-25257

Proof-of-concept exploit for CVE-2022-25257: CSRF parameter injection in SAS Logon 9.4 enabling warning-message spoofing for phishing attacks.

View Repository
64 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-25257

SAS Logon 9.4 allows warning-message injection.

Discovered: February 15, 2022

Affected Versions:

9.4

POC Exploit:

SASLogon/csrf has one parameter called "target"

This parameter affects the warning message for the URL the user was about to open (but, because of the unknown origin, the system blocks it). By changing the parameter, one can write a long fake statement that can affect an unaware user.

Example for a payload: https://example:8343/SASLogon/csrf?target=Hello%20Dear%20customers%20during%20the%20corona%20pandemic%20our%20new%20website%20is%20at%20http://evilRobertsWeb.com%20please%20visit%20this%20link%20to%20reset%20the%20password

Pictures:

image
Download Tool