# Exploit Title: WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin) # Date: 2018-12-23 # Exploit Author: linfeng # Vendor Homepage:https://github.com/wstmall/wstmart/ # Software Link:http://www.wstmart.net/ # Version: WSTMart 2.0.8_181212 # CVE :CVE-2018-19138 # 0x02 CSRF PoC # 18/5000 # Function point: background management - staff management - login account # poc: # 1234.html Document