PT-2018-9924 · Baijia · Baijiacms
Publicado
2018-04-27
·
Atualizado
2019-12-03
·
CVE-2018-10503
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
baijiacms V4 version v4 1 4 20170105
Description:
An issue in index.php allows for CSRF attacks, enabling unauthorized actions such as adding an administrator account via "op=edituser", changing the administrator password via "op=changepwd", or deleting an account via "op=deleteuser".
Recommendations:
For baijiacms V4 version v4 1 4 20170105, consider implementing CSRF protection measures to prevent unauthorized actions, such as validating user requests and ensuring that sensitive operations like adding, modifying, or deleting accounts require proper authentication and authorization.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Baijiacms