PT-2024-33202 · Unknown · Dingfanzu Cms

Published

2024-10-16

·

Updated

2024-10-18

·

CVE-2024-48758

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions dingfanzu CMS version 1.0
Description The issue is a Cross-Site Request Forgery (CSRF) that allows a remote attacker to execute arbitrary code via the addPro parameter of the doAdminAction.php component. This enables unauthorized actions.
Recommendations For dingfanzu CMS version 1.0, patch immediately and validate user requests to prevent unauthorized actions. As a temporary workaround, consider restricting access to the doAdminAction.php component or disabling the addPro parameter until a patch is available.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-48758

Affected Products

Dingfanzu Cms