07FLYCMS
cpe:2.3:a:07fly:07flycms:*:*:*:*:*:*:*
- 1.3.9
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in 07FLYCMS version 1.3.9. This vulnerability allows remote attackers to execute arbitrary code by manipulating the 'id' parameter in the 'del.html' component.
Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code on the server where 07FLYCMS is installed.
To reproduce this vulnerability, send a request to the 'del.html' component with a crafted 'id' parameter. The request must be made in a way that bypasses the application's CSRF protections, such as through a malicious link or script that exploits the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.