Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZUUSE BEIMS ContractorWeb .NET 跨站请求伪造漏洞
Vulnerability Description
ZUUSE BEIMS ContractorWeb .NET是澳大利亚ZUUSE公司的一套基础设施管理软件。 ZUUSE BEIMS ContractorWeb .NET 5.18.0.0版本中的/CWEBNET/* authenticated页面存在跨站请求伪造漏洞。远程攻击者可利用该漏洞创建用户,更改邮件地址或执行其他操作。
CVSS Information
N/A
Vulnerability Type
N/A