vendor:
GreenCMS
by:
xichao
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: GreenCMS
Affected Version From: v2.3.0603
Affected Version To: v2.3.0603
Patch Exists: YES
Related CWE: CVE-2018-11670
CPE: a:greencms:greencms:2.3.0603
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
GreenCMS v2.3.0603 CSRF vulnerability get webshell
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content parameter to index.php?m=admin&c=media&a=fileconnect.
Mitigation:
Implementing a secure configuration posture, including the application of the latest security patches, can help to reduce the risk of exploitation of this vulnerability.