RULE(RULE ID:330935)

Rule General Information
Release Date: 2020-08-26
Rule Name: GreenCMS v2.3.0603 Cross Site Request Forgery Vulnerability (CVE-2018-11670)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content parameter to index.php?m=admin&c=media&a=fileconnect.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:44825
https://github.com/GreenCMS/GreenCMS/issues/108
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/GreenCMS/GreenCMS