Acora CMS
cpe:2.3:a:ddsn:cm3_acora_content_management_system:*:*:*:*:*:*:*
- 10.1.1
A Cross-Site Request Forgery (CSRF) vulnerability exists in Acora CMS version 10.1.1. This issue allows attackers to manipulate authenticated users into executing unauthorized actions, such as deleting accounts or creating users. The vulnerability arises from insufficient CSRF protections, enabling exploitation through crafted requests that take advantage of the victim's active session, potentially disrupting user management functions.
Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of authenticated users, such as deleting accounts or creating new users, thereby disrupting normal user management processes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.