A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.
References
Link | Resource |
---|---|
https://github.com/zyx0814/dzzoffice | Third Party Advisory |
https://github.com/zyx0814/dzzoffice/issues/223 | Exploit Issue Tracking Third Party Advisory |
http://dzzoffice.com | Product |
Configurations
Information
Published : 2022-10-27 13:15
Updated : 2022-10-31 08:57
NVD link : CVE-2022-43340
Mitre link : CVE-2022-43340
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
dzzoffice
- dzzoffice