CVE-2019-16678: CSRF
Published Sep 21, 2019
·Updated
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
Affected Software
1 affected component
YzmCMS YzmCMS=5.3
Event History
Sep 21, 2019
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16678?
CVE-2019-16678 has been classified with a severity rating that indicates it can lead to denial of service due to the CSRF vulnerability.
2
How do I fix CVE-2019-16678?
To fix CVE-2019-16678, ensure that you implement CSRF protection mechanisms such as tokens for state-changing requests in YzmCMS 5.3.
3
What impact does CVE-2019-16678 have on YzmCMS 5.3?
CVE-2019-16678 can allow an attacker to exploit the CSRF vulnerability to cause a denial of service by modifying routing rules.
4
Is CVE-2019-16678 present in earlier versions of YzmCMS?
CVE-2019-16678 specifically affects YzmCMS version 5.3, and earlier versions may not be impacted.
5
What type of attacks does CVE-2019-16678 enable?
CVE-2019-16678 enables CSRF attacks that can result in a denial of service condition through unauthorized route manipulations.