First published: Sat Nov 18 2023(Updated: )
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dreamer Cms Project Dreamer Cms | =4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48017 is a vulnerability in Dreamer_cms 4.1.3 that allows for Cross Site Request Forgery (CSRF) attacks via Add permissions to CSRF in Permission Management.
CVE-2023-48017 has a severity rating of 8.8 (high).
CVE-2023-48017 affects Dreamer_cms 4.1.3 by enabling Cross Site Request Forgery (CSRF) attacks through the Add permissions to CSRF in Permission Management feature.
To fix CVE-2023-48017, update Dreamer_cms to a version that does not have this vulnerability or apply the necessary patches provided by the Dreamer_cms project.
You can find more information about CVE-2023-48017 at the following link: [GitHub - moonsabc123/dreamer_cms - Add permissions to CSRF in Permission Management](https://github.com/moonsabc123/dreamer_cms/blob/main/Add%20permissions%20to%20CSRF%20in%20Permission%20Management.md)