CVE-2024-50966: Timgreen Dingfanzu CMS

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.

Affected products

  • Timgreen Dingfanzu CMS: version 1.0 only

Published 2024-11-08. Last modified 2026-06-17.