PT-2024-33016 · Unknown · Dingfanzu Cms

Published

2024-10-28

·

Updated

2025-05-27

·

CVE-2024-48191

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions dingfanzu CMS version 1.0
Description The issue is related to a Cross-Site Request Forgery (CSRF) in the component /admin/doAdminAction.php?act=delAdmin&id=17. This allows for unauthorized actions to be performed.
Recommendations For dingfanzu CMS version 1.0, as a temporary workaround, consider restricting access to the /admin/doAdminAction.php endpoint until a patch is available. Avoid using the id parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-48191

Affected Products

Dingfanzu Cms