First published: Mon Oct 14 2019(Updated: )
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms Jizhicms | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-17593 is high with a CVSS score of 8.8.
CVE-2019-17593 allows CSRF attacks on admin.php/Admin/adminadd.html in JIZHICMS 1.5.1, enabling unauthorized addition of an administrator.
To fix the CVE-2019-17593 vulnerability in JIZHICMS 1.5.1, apply the latest security patch or upgrade to a patched version of JIZHICMS.
The Common Weakness Enumeration (CWE) of CVE-2019-17593 is CWE-352: Cross-Site Request Forgery (CSRF).
You can find more information about CVE-2019-17593 at the following reference: https://github.com/Cherry-toto/jizhicms/issues/1