Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cerb 跨站请求伪造漏洞
Vulnerability Description
Cerb是一套基于Web的商业协作和自动化平台。 Cerb 7.0.3及之前版本的ajax.php脚本中存在跨站请求伪造漏洞。远程攻击者可通过执行saveWorkerPeek操作利用该漏洞添加管理员账户。
CVSS Information
N/A
Vulnerability Type
N/A