CVE-2022-37730

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
07/09/2022
Last modified:
13/09/2022

Description

In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to forge a link to trick him to click on a malicious link or visit a page containing attack code, and send a request to the server (corresponding to the identity authentication information) as the victim without the victim's knowledge.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ftcms:ftcms:2.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools