Fanli2012 Native-PHP-CMS Improper Authorization Vulnerability in Backend Component

Vulnerability

A critical vulnerability has been identified in Fanli2012 native-php-cms version 1.0. The issue arises from improper authorization handling in the backend file '/fladmin/sysconfig_doedit.php', allowing attackers to modify backend data without authorization. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for unauthorized modification of backend data.

Reproduction

To reproduce this vulnerability, log into the application as an administrator. Once logged in, send a POST request to '/fladmin/sysconfig_doedit.php' with the 'varname', 'id', 'info', and 'value' fields. The 'id' field should be set to 15, and the 'value' field can be set to 16. After sending the request, refresh the 'sysconfig_list.php' page to see the changes take effect.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
6.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.