Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save fir3storm/ac219fe6deb237828ff86dd8cba5a9d7 to your computer and use it in GitHub Desktop.
Save fir3storm/ac219fe6deb237828ff86dd8cba5a9d7 to your computer and use it in GitHub Desktop.
CWP Web Control Panel "Recover Password" component bypass
  1. Visit the CWP Control Panlel url :
  2. Enter a valid username and any email address (here the attacker will put his email id) Capture the request in Burp Suite

image image Click Forward In the next intercept, change the value "0" to "1" image image

Forward the request image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment