VYPR
Medium severity6.5NVD Advisory· Published Jul 6, 2023· Updated Jun 17, 2026

CVE-2023-37131

CVE-2023-37131

Description

A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • YZNCMS/YZNCMScpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: =1.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.