Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the authentication of administrators for requests that change the email address via the act[update] action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpFoX 'account/settings/account/index.php'跨站请求伪造漏洞
Vulnerability Description
phpFox是一款基于PHP和MySQL开放源码的社交网络的软件包。 phpFoX 1.6.21版本的account/settings/account/index.php中存在跨站请求伪造漏洞。远程攻击者可以借助act[update]操作,劫持管理员认证信息来要求改变邮件地址。
CVSS Information
N/A
Vulnerability Type
N/A