Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote attackers to perform unauthorized actions as an arbitrary user via the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Notes, (5) Search, (6) Mail, or (7) Filemanager module; the (9) summary page; or unspecified other files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHProjekt lib/lib.inc.php check_csrftoken函数 多个跨站请求伪造漏洞
Vulnerability Description
PHProjekt 5.2.0版本的lib/lib.inc.php中的check_csrftoken函数存在多个跨站请求伪造漏洞。当magic_quotes_gpc被禁用时,远程攻击者可以借助(1)项目, (2)联系,(3)Helpdesk,(4)注意事项,(5)搜索,(6)邮件或(7)文件管理器模块,(9)概述页或其他未明文件,以任意用户的身份执行未授权操作。
CVSS Information
N/A
Vulnerability Type
N/A