Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Albert5888

#51676of 53,634
4.3Total CVSS
Vulnerabilities · 1
PT-2022-24370
4.3
2022-09-13
Unknown · Shopxian Cms · CVE-2022-38329
**Name of the Vulnerable Software and Affected Versions** Shopxian CMS version 3.0.0 **Description** A CSRF issue allows deletion of a specified column via the "index.php/contents-admin cat-finderdel-model-ContentsCat.html" endpoint, specifically when the `id` parameter is set to 17. **Recommendations** For Shopxian CMS version 3.0.0, as a temporary workaround, consider restricting access to the "index.php/contents-admin cat-finderdel-model-ContentsCat.html" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.