8.8
CVSSv3

CVE-2022-43031

Published: 09/11/2022 Updated: 10/11/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

DedeCMS v6.1.9 exists to contain a Cross-Site Request Forgery (CSRF) which allows malicious users to arbitrarily add Administrator accounts and modify Admin passwords.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dedecms dedecms 6.1.9

Github Repositories

Dedecmsv6

CVE-2022-43031 Log in to the website background using the website default password admin/admin Visit the csrf attack website,Add an administrator user The user was successfully created but could not log in There was a problem with the system code The created users could not log in After checking the code, we found that the stored password was not the password we entered