CVE-2023-43275: CSRF
Published Nov 16, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalogadd.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.
Affected Software
1 affected component
DedeCMS Dedecms=5.7
Event History
Nov 16, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-43275?
CVE-2023-43275 is a Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in the 110 backend management interface.
2
How does CVE-2023-43275 work?
CVE-2023-43275 allows attackers to create crafted web pages by exploiting a lack of verification of the token value in the submitted form.
3
What is the severity level of CVE-2023-43275?
The severity level of CVE-2023-43275 is high, with a severity value of 8.8.
4
Which software version is affected by CVE-2023-43275?
DedeCMS v5.7 is affected by CVE-2023-43275.
5
How can I fix CVE-2023-43275?
To fix CVE-2023-43275, it is recommended to apply the latest security patches or updates provided by the DedeCMS vendor.