漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CSRF in MegaBIP
Vulnerability Description
Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php?id=7,7,0" lacks protection mechanisms.
A user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If the victim is a logged in administrator, this could lead to creation of new accounts and granting of administrative permissions.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
MegaBIP 安全漏洞
Vulnerability Description
MegaBIP是MegaBIP公司的一个用于创建BIP网站的软件。 MegaBIP 5.15之前版本存在安全漏洞,该漏洞源于容易受到跨站请求伪造攻击,导致已登录的管理员用户可能被诱导访问恶意网站。
CVSS Information
N/A
Vulnerability Type
N/A