Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/779789571/zzcms/blob/main/README.md | |
https://github.com/forget-code/zzcms/issues/6 | issue tracking exploit |
http://www.zzcms.net/about/download.html | product |