CVE-2022-23887: CSRF
Published Jan 28, 2022
·Updated
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/adminmanage/delete.
Affected Software
1 affected component
YzmCMS YzmCMS=6.3
Event History
Jan 28, 2022
CVE Published
via MITRE·08:44 PM
Data Sourced
via MITRE·08:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-23887?
CVE-2022-23887 is categorized as a high severity vulnerability due to its potential to allow unauthorized account deletions.
2
How do I fix CVE-2022-23887?
To fix CVE-2022-23887, ensure that proper CSRF protection mechanisms are implemented in the Yzmcms application.
3
What impact does CVE-2022-23887 have on user accounts?
CVE-2022-23887 allows attackers to arbitrarily delete user accounts, posing a significant risk to user data and application integrity.
4
Which version of Yzmcms is affected by CVE-2022-23887?
CVE-2022-23887 specifically affects Yzmcms version 6.3.
5
Is there a known exploit for CVE-2022-23887?
Yes, CVE-2022-23887 has been identified as a vulnerability that attackers can exploit to execute unauthorized actions.