vendor:
DamiCMS
by:
bay0net
5.5
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: DamiCMS
Affected Version From: DAMICMS_V6.0.0
Affected Version To: DAMICMS_V6.0.0
Patch Exists: NO
Related CWE:
CPE: a:damicms:damicms:6.0.0
Platforms Tested:
2018
DAMICMS 6.0.0 – Cross-Site Request Forgery (Add Admin)
DamiCMS v6.0.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.
Mitigation:
Implement CSRF tokens to validate requests and prevent unauthorized actions.