PT-2023-28316 · Douhaocms · Douhaocms

Published

2023-10-30

·

Updated

2024-09-09

·

CVE-2023-42323

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DouHaocms version 3.3
Description A Cross Site Request Forgery (CSRF) issue allows a remote attacker to execute arbitrary code via the adminAction.class.php file. This can be exploited to perform unauthorized actions on the affected system.
Recommendations For DouHaocms version 3.3, consider disabling access to the adminAction.class.php file until a patch is available to prevent exploitation of the CSRF issue.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-42323

Affected Products

Douhaocms