vendor:
Kryn.cms
by:
7.5
CVSS
HIGH
Cross-Site Request Forgery, HTML Injection
352
CWE
Product Name: Kryn.cms
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Kryn.cms Cross-Site Request Forgery and HTML Injection Vulnerabilities
The vulnerabilities in Kryn.cms allow a remote attacker to perform administrative actions, gain unauthorized access, delete data, execute arbitrary script or HTML code, and steal authentication credentials.
Mitigation:
Implement proper input validation and authentication mechanisms, and apply security patches.