A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.
References
Link | Resource |
---|---|
https://github.com/TheHermione/CVE-2024-45264 | Third Party Advisory |
https://skyss.ru | Product |
Configurations
History
No history.
Information
Published : 2024-08-27 16:15
Updated : 2024-08-30 15:02
NVD link : CVE-2024-45264
Mitre link : CVE-2024-45264
CVE.ORG link : CVE-2024-45264
JSON object : View
Products Affected
skyss
- arfa-cms
CWE
CWE-352
Cross-Site Request Forgery (CSRF)