Cross Site Request Forgery in profile's "SSH Keys" leads to unauthorized access to the system in ikus060/rdiffweb
Sep 14th 2022
While adding SSH public keys to the profile, the server accepts the GET request which results in adding an SSH public key to the profile and leads to unauthorised access to the system and backups.
Proof of Concept
Open the below url after logging in to the demo site.SSH Public key will be added to the profile.