Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ClickHeat 跨站请求伪造漏洞
Vulnerability Description
ClickHeat是Labsmedia云计算中心开发的一套开源的网站热图生成工具。该工具可统计一个页面上用户点击的热度分布图,且支持中文显示。 ClickHeat 1.14及之前版本中存在跨站请求伪造漏洞。远程攻击者可通过对index.php脚本执行config操作利用该漏洞更改管理员密码。
CVSS Information
N/A
Vulnerability Type
N/A