Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FrontAccounting 跨站请求伪造漏洞
Vulnerability Description
FrontAccounting(FA)是FrontAccounting公司的一套适用于中小型企业ERP供应链的财务软件。该软件包括采购订单、商品票据和账务分类与预算等模块。 FrontAccounting 2.4.3版本中存在跨站请求伪造漏洞。远程攻击者可借助admin/users.php文件利用该漏洞添加用户账户。
CVSS Information
N/A
Vulnerability Type
N/A