First published: Mon Nov 13 2023(Updated: )
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48063 refers to a CSRF vulnerability in dreamer_cms 4.1.3 that allows an attacker to delete a theme project via /admin/category/delete.
CVE-2023-48063 has a severity value of 4.3 (medium).
An attacker can exploit CVE-2023-48063 by sending a malicious request to the /admin/category/delete endpoint in dreamer_cms 4.1.3.
Currently, there is no known fix available for CVE-2023-48063. It is recommended to update to a patched version of dreamer_cms once it becomes available.
You can find more information about CVE-2023-48063 on the GitHub page provided in the following link: [GitHub - CSRF vulnerability in dreamer_cms](https://github.com/CP1379767017/cms/blob/dreamcms_vul/There%20is%20a%20CSRF%20vulnerability%20at%20th%20menu%20management%20location.md)