Описание
ThinkCMF Cross Site Request Forgerly (CSRF) vulnerability
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF, which can add an admin account.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-18151
- https://github.com/thinkcmf/thinkcmf/issues/580
- https://github.com/thinkcmf/thinkcmf/issues/736
- https://github.com/thinkcmf/thinkcmf/commit/321faa20865e74540e5f0a63e4c3f4ea75093d59
- https://github.com/thinkcmf/thinkcmf/commit/b61636134aa57d4693967f35772200c779099740
Пакеты
Наименование
thinkcmf/thinkcmf
composer
Затронутые версииВерсия исправления
< 6.0.8
6.0.8
Связанные уязвимости
CVSS3: 6.5
nvd
больше 4 лет назад
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.