Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pacific Timesheet 'user/user-set.do'跨站请求伪造漏洞
Vulnerability Description
Pacific Timesheet的user/user-set.do存在跨站请求伪造(CSRF)漏洞,远程攻击者可以通过new_admin操作劫持管理员的认证请求,创建新的管理员用户。
CVSS Information
N/A
Vulnerability Type
N/A