PT-2023-28756 · Dedecms · Dedecms

CVE-2023-43275

·

Publicado

2023-11-16

·

Atualizado

2024-08-14

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS version 5.7
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability in the backend management interface. This vulnerability allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form via the "/catalog add.php" API endpoint.
Recommendations For DedeCMS version 5.7, consider disabling access to the "/catalog add.php" endpoint until a patch is available to prevent exploitation. Restrict the submission of forms with unverified token values to minimize the risk of CSRF attacks.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-43275

Produtos afetados

Dedecms