
Proof-of-concept demonstrating Cross-Site Request Forgery in Minical 1.0.0, enabling unauthorized user addition, deletion, and modification of sensitive data.
Minical 1.0.0 is vulnerable to Cross-Site Request Forgery.
Vendor: https://github.com/minical/minical
Demo Application: https://demo.minical.io/
The application does not have any CSRF protection, hence a specially crafted HTTP request can be used to,
The payloads for different attacks can be generated using the Generate CSRF POC tool in BurpSuite.
Example:
Add New User:
