PT-2021-10387 · Zzcms · Zzcms
Zhhhy
·
Published
2021-12-09
·
Updated
2021-12-13
·
CVE-2020-19682
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ZZZCMS version 1.7.1
Description:
A Cross Site Request Forgery (CSRF) issue exists via the
save user function in the "save.php" endpoint. This allows for unauthorized actions to be performed on behalf of a user.Recommendations:
For ZZZCMS version 1.7.1, as a temporary workaround, consider disabling the
save user function in save.php until a patch is available. Restrict access to the save.php endpoint to minimize the risk of exploitation.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zzcms