First published: Fri Jun 24 2022(Updated: )
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-33121 is high with a severity value of 8.1.
The Cross-Site Request Forgery (CSRF) vulnerability in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files by clicking on a malicious link.
An attacker can exploit CVE-2022-33121 by tricking a user into clicking on a malicious link that triggers a Cross-Site Request Forgery (CSRF) attack.
CVE-2022-33121 affects MiniCMS version 1.11.
At the moment, there is no official fix available for CVE-2022-33121. It is recommended to apply security patches or updates provided by the vendor when they become available.