martinzhou2015/SRCMS-dev

martinzhou2015/SRCMS-dev

Releases0
Stars10
SRCMS Dev Version

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.

4.3 MEDIUM

SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.