Skip to content

glFusion CMS 1.7.9 is affected by a Cross Site Request...

Moderate severity Unreviewed Published Dec 15, 2021 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

No package listedSuggest a package

Affected versions

Unknown

Patched versions

Unknown

Description

glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.

References

Published by the National Vulnerability Database Dec 14, 2021
Published to the GitHub Advisory Database Dec 15, 2021
Last updated Feb 1, 2023

Severity

Moderate

EPSS score

0.101%
(43rd percentile)

Weaknesses

CVE ID

CVE-2021-44948

GHSA ID

GHSA-65cr-jw24-wv57

Source code

No known source code

Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.

Learn more about GitHub language support

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.