CVE-2024-22939
HIGHFlyCms 1.0 - Cross-Site Request Forgery via Article Category Edit
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-22939. PoCs published by NUDTTAN91.
AI-analyzed exploit summary This repository contains a functional CSRF PoC for CVE-2024-22939, targeting FlyCms v1.0 via the `/system/article/category_edit` endpoint. The PoC includes a crafted HTML form that demonstrates the vulnerability by submitting a malicious request to modify a category name.
Description
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
Exploits (1)
This repository contains a functional CSRF PoC for CVE-2024-22939, targeting FlyCms v1.0 via the `/system/article/category_edit` endpoint. The PoC includes a crafted HTML form that demonstrates the vulnerability by submitting a malicious request to modify a category name.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H