First published: Wed Mar 15 2023(Updated: )
A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes within the application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms Jizhicms | =2.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CSRF vulnerability in Jizhicms v2.4.5 is CVE-2023-27234.
The severity of CVE-2023-27234 is medium (6.5).
This CSRF vulnerability in Jizhicms v2.4.5 allows attackers to make arbitrary configuration changes within the application by tricking authenticated users into performing unwanted actions.
The CSRF vulnerability in Jizhicms v2.4.5 affects version 2.4.5 of the software.
At the moment, there is no known fix available for CVE-2023-27234. It is recommended to follow the guidance provided by the software vendor or developer.