Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication of the administrator for requests that reset the administrator password via a POST to admin/ with an update action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AlegroCart 跨站请求伪造漏洞
Vulnerability Description
AlegroCart存在跨站请求伪造(CSRF)漏洞,远程攻击者可以向admin/发送进行更新操作的POST请求,然后劫持管理员对重置管理员密码请求的认证。
CVSS Information
N/A
Vulnerability Type
N/A