An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/GreenCMS/GreenCMS/issues/109 | third party advisory exploit |
https://www.exploit-db.com/exploits/44826/ | exploit vdb entry third party advisory |