Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KrisonAV CMS 跨站请求伪造漏洞
Vulnerability Description
KrisonAV CMS是一套基于Codecharge Studio(Web应用开发工具)和Artisteer(网站模板设计工具)的内容管理系统(CMS)。该系统支持自动生成分类、文件下载和可扩展等。 KrisonAV CMS 3.0.2之前版本的users_maint.html页面存在跨站请求伪造漏洞。远程攻击者可通过发送特制的请求利用该漏洞创建用户账户。
CVSS Information
N/A
Vulnerability Type
N/A