GetSimple CMS Custom JS 0.1 CSRF /...

- AV AC AU C I A
发布: 2021-05-02
修订: 2025-04-13

The Custom JS plugin version 0.1 for GetSimple CMS suffers from a cross site request forgery vulnerability that allows remote unauthenticated attackers to inject arbitrary client-side code into authenticated administrators browsers, which results in remote code execution on the hosting server, when an authenticated administrator visits a malicious third party website.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息