漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CSRF in PHP Jabbers scripts
Vulnerability Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
PHPJabbers Appointment Scheduler 跨站请求伪造漏洞
Vulnerability Description
PHPJabbers Appointment Scheduler是PHPJabbers公司的一款预约调度软件 PHPJabbers Appointment Scheduler 4.1之前版本存在跨站请求伪造漏洞,该漏洞源于缺乏CSRF令牌或适当的SameSite属性,可能导致攻击者在已认证用户环境下发送未经授权的请求,从而执行未授权的管理操作,如创建新的管理员账户。
CVSS Information
N/A
Vulnerability Type
N/A