# Exploit Title: Admin Account take over Via CSRF # Google Dork: N/A # Date: 17-12-2018 # Exploit Author: Sainadh Jamalpur # Vendor Homepage: https://www.phpjabbers.com/hotel-booking-system/ # Software Link: https://demo.phpjabbers.com/1545033057_422/index.php?controller=pjAdmin&action=pjActionIndex # Version: 3.4 # Tested on: Windows x64/ Kali linux x64 # CVE : N/A ************************Description:********************** The online hotel reservation system is built in PHP and uses MySQL to store data. The script provides a powerful room booking and reservation management functionality and allows you to install a clear call-to-action tool on your hotel website which will impact conversions and increase bookings. Our room booking system is highly customizable and compatible with various website types. *************************Vulnerability Description:**************** An attacker can take the admin account via sending the Malicious link to the authenticated user then the Victim clicks on the malicious link then the admin password is change ************************************ PoC**************************************