07FLYCMS
cpe:2.3:a:07fly:07flycms:*:*:*:*:*:*:*
- <= 1.3.9
A cross-site request forgery (CSRF) vulnerability has been identified in 07FLYCMS, 07FLY-CMS, and 07FlyCRM versions through 1.3.9. This vulnerability allows for the manipulation of requests in a way that could be exploited remotely, without the need for authentication. The issue arises because the application does not adequately verify whether a request was intentionally made by the user.
Exploitation of this vulnerability allows for cross-site request forgery, where an attacker can trick a user into performing actions they did not intend to.
To reproduce this vulnerability, send a request to the 'del.html' endpoint of the OaLeave component with a valid 'id' parameter. This request must be made without proper verification, taking advantage of the application's lack of CSRF protection.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.