Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) status parameter to admin/stats_monthly_sales.php or (2) country parameter in a process action to admin/create_account_process.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
osCMax 跨站请求伪造漏洞
Vulnerability Description
osCMax是一套基于PHP的开源电子商务系统/购物车应用程序,它支持多语言、SSL安全交易、多种支付方式、地区运费换算、打印发票等。 osCMax 2.5.1之前版本的管理面板中存在跨站请求伪造漏洞,该漏洞源于admin/stats_monthly_sales.php脚本没有充分过滤‘status’参数;admin/create_account_process.php脚本没有充分过滤‘country’参数。远程攻击者可利用该漏洞实施SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A