First published: Wed Nov 09 2022(Updated: )
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =6.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43031 is a vulnerability in DedeCMS v6.1.9 that allows attackers to perform Cross-Site Request Forgery (CSRF) attacks.
The severity of CVE-2022-43031 is classified as high, with a severity value of 8.8.
CVE-2022-43031 affects DedeCMS v6.1.9 by allowing attackers to arbitrarily add Administrator accounts and modify Admin passwords through Cross-Site Request Forgery (CSRF) attacks.
No official fixes are available for CVE-2022-43031 at the moment, but it is recommended to update to a patched version once it becomes available.
The Common Weakness Enumeration (CWE) ID for CVE-2022-43031 is CWE-352, which is related to Cross-Site Request Forgery (CSRF) vulnerabilities.