Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Tinyfisher

#29870de 53,640
8.8CVSS total
Vulnerabilidades · 1
PT-2018-9738
8.8
2018-04-17
Tuzi · Tuzicms · CVE-2018-10185
Name of the Vulnerable Software and Affected Versions: TuziCMS version 2.0.6 Description: An issue in TuziCMS allows for a CSRF vulnerability, enabling the addition of an admin account. This is demonstrated through a history.pushState call. Recommendations: For TuziCMS version 2.0.6, update to a newer version that contains a fix for this issue, if available. As a temporary workaround, consider implementing CSRF protection measures to prevent unauthorized actions.