### [CVE-2019-11374](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11374) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. ### POC #### Reference - http://packetstormsecurity.com/files/152603/74CMS-5.0.1-Cross-Site-Request-Forgery.html - https://www.exploit-db.com/exploits/46738/ #### Github - https://github.com/0day404/vulnerability-poc - https://github.com/ARPSyndicate/cvemon - https://github.com/J1ezds/Vulnerability-Wiki-page - https://github.com/KayCHENvip/vulnerability-poc - https://github.com/SexyBeast233/SecBooks - https://github.com/Threekiii/Awesome-POC - https://github.com/XiaomingX/awesome-poc-for-red-team - https://github.com/d4n-sec/d4n-sec.github.io - https://github.com/hktalent/bug-bounty