Cross Site Request Forgery Vulnerability in Phpsysinfo by Phpsysinfo
CVE-2023-49006

6.5MEDIUM

Key Information:

Vendor

PHPsysinfo

Vendor
CVE Published:
19 December 2023

What is CVE-2023-49006?

A Cross Site Request Forgery (CSRF) vulnerability exists in Phpsysinfo version 3.4.3, which enables remote attackers to exploit the XML.php file. This exploitation can allow attackers to craft malicious web pages that, when accessed by users, can lead to unauthorized access to sensitive information, compromising the security of the affected system.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.