CVE-2022-43031: CSRF
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43031?
CVE-2022-43031 is a vulnerability in DedeCMS v6.1.9 that allows attackers to perform Cross-Site Request Forgery (CSRF) attacks.
What is the severity of CVE-2022-43031?
The severity of CVE-2022-43031 is classified as high, with a severity value of 8.8.
How does CVE-2022-43031 affect DedeCMS?
CVE-2022-43031 affects DedeCMS v6.1.9 by allowing attackers to arbitrarily add Administrator accounts and modify Admin passwords through Cross-Site Request Forgery (CSRF) attacks.
Are there any fixes available for CVE-2022-43031?
No official fixes are available for CVE-2022-43031 at the moment, but it is recommended to update to a patched version once it becomes available.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-43031?
The Common Weakness Enumeration (CWE) ID for CVE-2022-43031 is CWE-352, which is related to Cross-Site Request Forgery (CSRF) vulnerabilities.