CVE Database · CVE-2021-33396
CVSS v3.1
6.5
EPSS
0.32%
Published
Feb 15, 2023
Modified
Mar 20, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NWeaknesses (CWE)
Affected Products (1)
References (2)