First published: Thu Jul 06 2023(Updated: )
A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yzncms | =1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37131 is a Cross-Site Request Forgery (CSRF) vulnerability in YznCMS v1.1.0 that allows attackers to change the Administrator password.
CVE-2023-37131 has a severity rating of 6.5 out of 10, which is considered medium.
CVE-2023-37131 allows attackers to exploit a vulnerability in the /public/admin/profile/update.html component of YznCMS v1.1.0 to send a crafted POST request and change the Administrator password.
No, CVE-2023-37131 only affects YznCMS version 1.1.0.
To mitigate CVE-2023-37131, it is recommended to update YznCMS to a patched version or apply any available security patches provided by the vendor.