In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://gitee.com/gxlcms/gxlcms_news_system_2/issues/ILVLP | broken link |
http://www.gxlcms.com/ | product |
https://exchange.xforce.ibmcloud.com/vulnerabilities/148132 | third party advisory |