Fanli2012 native-php-cms
cpe:2.3:a:native-php-cms_project:native-php-cms:*:*:*:*:*:*:*
- 1.0
A critical vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises from improper authorization handling in the backend file '/fladmin/sysconfig_doedit.php', allowing attackers to modify backend data without authorization. This vulnerability can be exploited remotely.
Exploitation of this vulnerability allows for unauthorized modification of backend data.
To reproduce this vulnerability, log into the application as an administrator. Once logged in, send a POST request to '/fladmin/sysconfig_doedit.php' with the 'varname', 'id', 'info', and 'value' fields. The 'id' field should be set to 15, and the 'value' field can be set to 16. After sending the request, refresh the 'sysconfig_list.php' page to see the changes take effect.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.