Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in engine/modules/imagepreview.php in Datalife Engine 6.7 allows remote attackers to hijack the authentication of arbitrary users for requests that use a modified image parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Softnews Media Group DataLife Engine 'engine/modules/imagepreview.php' 跨站请求伪造漏洞
Vulnerability Description
DataLife Engine是多用户新闻游标用于组织在因特网上的传播各种新闻媒体,并可以实现新闻条目和内容的编辑和发布。 Datalife 引擎6.7版本的engine/modules/imagepreview.php中存在跨站请求伪造漏洞。远程攻击者通过对运行一个修改过的图像参数的请求,劫持任意用户的认证权限。
CVSS Information
N/A
Vulnerability Type
N/A