Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-38329

Description

A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, potentially causing the administrator to perform unintended actions on an affected system. The vulnerability could allow attackers to modify or delete specific content through crafted requests, potentially leading to data loss and system integrity issues.

POC

Reference

- https://albert5888.github.io/posts/CVE-2022-38329/

- https://github.com/albert5888/CVE-Issues/blob/main/CVE-2022-38329/file.md

- https://github.com/zhangqiquan/shopxian_cms/issues/4

Github

No PoCs found on GitHub currently.