PT-2024-33073 · Unknown · Dingfanzu Cms

Published

2024-10-28

·

Updated

2025-05-27

·

CVE-2024-48291

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions dingfanzu CMS version 1.0
Description The issue is related to a Cross-Site Request Forgery (CSRF) in the /admin/doAdminAction.php endpoint, specifically when the act parameter is set to editAdmin and the id parameter is set to 17. This allows for unauthorized actions to be performed on the administrative interface.
Recommendations For dingfanzu CMS version 1.0, as a temporary workaround, consider disabling access to the /admin/doAdminAction.php endpoint until a patch is available. Restrict the use of the act and id parameters in this endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-48291

Affected Products

Dingfanzu Cms