PT-2026-50426 · Unknown · Simplcommerce
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SimplCommerce versions prior to commit 6233d73e
Description
Cross-site request forgery (CSRF) occurs in the NewsItemApiController. This issue allows an unauthenticated remote attacker to create or modify news items with administrator privileges by submitting a crafted form to the '/api/news-items' endpoint. The flaw is caused by a lack of anti-CSRF protection, which is a mechanism used to prevent unauthorized commands from being transmitted from a user that the web application trusts.
Recommendations
Update to the version containing commit 6233d73e or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplcommerce