First published: Tue Oct 17 2023(Updated: )
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dreamer Cms Project Dreamer Cms | =4.1.3 | |
=4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45904 is a Cross-Site Request Forgery (CSRF) vulnerability found in Dreamer CMS v4.1.3.
The severity of CVE-2023-45904 is high with a CVSS score of 8.8.
CVE-2023-45904 allows an attacker to perform unauthorized actions on behalf of authenticated users by tricking them into clicking on a malicious link or visiting a malicious website.
To fix CVE-2023-45904, it is recommended to update Dreamer CMS to the latest version or apply the patch provided by the vendor.
You can find more information about CVE-2023-45904 on the following GitHub page: [link](https://github.com/moonsabc123/dreamer_cms/blob/main/There%20is%20a%20csrf%20vulnerability%20in%20the%20variable%20management%20modification%20function.md).