Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Simple-Log 跨站请求伪造漏洞
Vulnerability Description
Simple-Log是一个基于PHP+MySQL的开源免费博客系统。 Simple-Log v1.6 存在跨站请求伪造漏洞,该漏洞源于Simple-Log未充分验证请求是否来自可信用户。攻击者可利用该漏洞通过组件“Simple-Log admin admin.php”获得特权并执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A