Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Dswjcms 跨站请求伪造漏洞
Vulnerability Description
Dswjcms是针对个人和个人的借贷推出的免费p2p开源项目,基于Thinkphp架构的行业系统,全自动安装模式,快速搭建P2P网站。 Dswjcms 1.6.4版本存在跨站请求伪造漏洞,该漏洞源于index.php/Dswjcms/User/tfAdd 组件中对于参数缺乏有效的验证与转义,经过身份验证的攻击者可以利用该漏洞任意添加管理员用户。
CVSS Information
N/A
Vulnerability Type
N/A