JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://jforum.com | product |
https://jforum.net/ | product |
https://sourceforge.net/p/jforum2/wiki2/NewFeatures281/ | third party advisory |
https://community.jforum.net/posts/list/248.page | mailing list release notes vendor advisory |
https://github.com/WULINPIN/CVE/blob/main/JForum/poc.html | third party advisory exploit |