CVE-2019-9652: CSRF
Published Mar 11, 2019
·Updated
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.
Affected Software
1 affected component
SDCMS SDCMS=1.7
Event History
Mar 11, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9652?
CVE-2019-9652 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2019-9652?
To fix CVE-2019-9652, update SDCMS to the latest version that addresses the vulnerability.
3
What type of vulnerability is CVE-2019-9652?
CVE-2019-9652 is a Cross-Site Request Forgery (CSRF) vulnerability that allows PHP code injection.
4
Which software versions are affected by CVE-2019-9652?
SDCMS version 1.7 is the only affected version according to CVE-2019-9652.
5
Can CVE-2019-9652 be exploited remotely?
Yes, CVE-2019-9652 can be exploited remotely if the attacker can initiate a malicious request.