|
|||
Rule General Information |
---|
Release Date: | 2022-04-19 | |
Rule Name: | Kirby CMS Cross Site Request Forgery Vulnerability | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Kirby CMS is a flexible and easy-to-use content management system suitable for various website projects, including personal blogs, corporate websites, and e-commerce platforms. There is a cross site request forgery vulnerability in versions 2.1.0 and earlier. Combining it with the existing identity authentication bypass path traversal vulnerability may lead to remote code execution. | |
Impact: | An attacker can launch a cross-site request forgery in the context of the affected software. Arbitrary script transmitted from a user that the software trusts can be executed in a successful exploit attempt. | |
Affected OS: | Windows, Linux, Others | |
Reference: | ||
Solutions |
---|
Please contact the software vendor to update the software patch. |