Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-12752
HistoryFeb 17, 2022 - 12:00 a.m.

YzmCMS Cross-site Request Forgery Vulnerability (CNVD-2022-12752)

2022-02-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
18

0.001 Low

EPSS

Percentile

43.4%

YzmCMS is an open source CMS (Content Management System).A cross-site request spoofing vulnerability exists in YzmCMS, which stems from insufficient validation in admin.add that the request is coming from a trusted user. An attacker could use this vulnerability to spoof malicious requests to trick victims into clicking through to perform sensitive actions.

CPENameOperatorVersion
yzmcms yzmcms veq6.3

0.001 Low

EPSS

Percentile

43.4%

Related for CNVD-2022-12752