CVE-2023-52073
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 8, 2024
Updated: Jan 11, 2024
CWE ID 352
Summary
CVE-2023-52073: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in FlyCms v1.0. This issue lies in the component /system/site/config_footer_update, allowing an attacker to submit malicious requests on behalf of an unsuspecting user, potentially leading to unintended actions or data modifications within the system. This vulnerability poses a serious threat to the security of FlyCms v1.0 installations, emphasizing the importance of prompt patching and implementation of CSRF tokens to mitigate the risk of such attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share