Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tina4 Stack 1.0.3 Cross-Site Request Forgery via profile
Vulnerability Description
Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credentials by submitting forged POST requests to the profile endpoint. Attackers can craft HTML forms targeting the /kim/profile endpoint with hidden fields containing malicious user data like passwords and email addresses to update administrator accounts without authentication.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Tina4 Stack 跨站请求伪造漏洞
Vulnerability Description
Tina4 Stack是Tina4公司的一个全站开发框架集合。 Tina4 Stack 1.0.3版本存在跨站请求伪造漏洞,该漏洞源于profile端点存在跨站请求伪造问题,可能导致攻击者修改管理员用户凭据。
CVSS Information
N/A
Vulnerability Type
N/A