Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/setup_edit.cgi in CosmoShop ePRO 10.05.00 allows remote attackers to hijack the authentication of administrators for requests that modify settings via a setup action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CosmoShop ePRO 跨站请求伪造漏洞
Vulnerability Description
CosmoShop ePRO是一套基于Magento的云电子商务系统。该系统能够快速完成域名设置、网店安装、服务器部署、产品上线等。 CosmoShop ePRO 10.05.00版本的cgi-bin/admin/setup_edit.cgi文件中存在跨站请求伪造漏洞。远程攻击者可借助setup操作利用该漏洞修改设置。
CVSS Information
N/A
Vulnerability Type
N/A