WUZHI.CMS.CSRF

description-logoDescription

This indicates an attack attempt against a Cross-Site Request-Forgery vulnerability in WUZHI CMS.
The vulnerability is due to insufficient sanitization of user supplied inputs in the application. An authenticated attacker may exploit this to reset the password of a common member in the context of an authorized user's session.

affected-products-logoAffected Products

WUZHI CMS 4.1.0

Impact logoImpact

Privilege Escalation: Remote attackers can leverage their privilege on the vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-03-03 15.787 Default_action:pass:drop
2019-12-03 15.737