ShishuoCMS Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability exists in ShishuoCMS version 1.1. This issue allows remote attackers to manipulate certain processing functions, potentially leading to unauthorized actions being performed on behalf of users.

Impact

Exploitation of this vulnerability allows for cross-site request forgery, where an attacker can trick a user into performing actions they did not intend to, such as adding an administrator.

Reproduction

To reproduce this vulnerability, upload a crafted CSRF proof-of-concept (PoC) to the server. Once uploaded, simulate an administrator clicking on the PoC. After the click, verify if the administrator has been successfully added.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.