PT-2021-10387 · Zzcms · Zzcms

Zhhhy

·

Published

2021-12-09

·

Updated

2021-12-13

·

CVE-2020-19682

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ZZZCMS version 1.7.1
Description: A Cross Site Request Forgery (CSRF) issue exists via the save user function in the "save.php" endpoint. This allows for unauthorized actions to be performed on behalf of a user.
Recommendations: For ZZZCMS version 1.7.1, as a temporary workaround, consider disabling the save user function in save.php until a patch is available. Restrict access to the save.php endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-19682

Affected Products

Zzcms