A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/hadagaga/vuln/blob/master/JFinalCMS/Cross_Site_Request_Forgery/Cross-Site-Request-Forgery.md | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.287269 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.287269 | Permissions Required Third Party Advisory |
https://vuldb.com/?submit.456042 | Third Party Advisory |
Configurations
History
11 Dec 2024, 17:34
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:jwillber:jfinalcms:1.0:*:*:*:*:*:*:* | |
First Time |
Jwillber jfinalcms
Jwillber |
|
Summary |
|
|
References | () https://github.com/hadagaga/vuln/blob/master/JFinalCMS/Cross_Site_Request_Forgery/Cross-Site-Request-Forgery.md - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.287269 - Permissions Required, Third Party Advisory | |
References | () https://vuldb.com/?id.287269 - Permissions Required, Third Party Advisory | |
References | () https://vuldb.com/?submit.456042 - Third Party Advisory |
09 Dec 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-09 01:15
Updated : 2024-12-11 17:34
NVD link : CVE-2024-12349
Mitre link : CVE-2024-12349
CVE.ORG link : CVE-2024-12349
JSON object : View
Products Affected
jwillber
- jfinalcms