LinZhaoguan pb-cms Cross-Site Request Forgery Vulnerability in Logout Component

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in LinZhaoguan pb-cms version 2.0, specifically within the Logout component. This vulnerability allows for the manipulation of requests in a way that the application cannot properly verify, potentially leading to unauthorized actions being performed on behalf of a user. The issue can be exploited remotely and requires user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, potentially allowing for changes to be made that could disrupt the application's normal functioning or integrity.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.