Icmsdev · Icms · CVE-2023-42321
**Name of the Vulnerable Software and Affected Versions**
icmsdev iCMS version 7.0.16
**Description**
A Cross Site Request Forgery (CSRF) issue allows a remote attacker to execute arbitrary code via the "user.admincp.php", "members.admincp.php", and "group.admincp.php" files. This can be exploited by tricking a user into performing unintended actions on the web application.
**Recommendations**
For version 7.0.16, consider disabling access to the "user.admincp.php", "members.admincp.php", and "group.admincp.php" files until a patch is available. Restricting access to these files can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.