CMS V1.0 Exposed to CSRF Attacks
CVE-2024-48758

Currently unrated

Key Information:

Vendor
dingfanzu
Vendor
CVE Published:
16 October 2024

Summary

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code

References

Timeline

  • Vulnerability published

.