A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.
References
Link Resource
https://gitee.com/MetInfo_1/MetInfo/issues/I5YM81?from=project-issue Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-07T00:00:00

Updated: 2022-12-07T00:00:00

Reserved: 2022-11-07T00:00:00


Link: CVE-2022-44849

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-12-07T03:15:10.373

Modified: 2022-12-12T14:23:50.193


Link: CVE-2022-44849

JSON object: View

cve-icon Redhat Information

No data.

CWE