Security Advisory

CVE-2023-37131

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-07-06 00:00:00
Last updated 2024-11-20 19:47:46
Assigner mitre
State PUBLISHED

Description

A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.