There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://www.iwantacve.cn/index.php/archives/156/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-03-11T01:00:00
Updated: 2024-08-04T21:54:45.046Z
Reserved: 2019-03-10T00:00:00
Link: CVE-2019-9652
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-11T01:29:00.373
Modified: 2024-11-21T04:52:03.527
Link: CVE-2019-9652
Redhat
No data.