A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://seacms.com | product |
https://www.seacms.net/ | product |
https://blog.csdn.net/sugaryzheng/article/details/133283101?spm=1001.2014.3001.5501 | third party advisory |