CVE-2018-10267

WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.
References
Link Resource
https://www.hackpwn.me/2018/04/21/1/ Exploit Third Party Advisory
https://github.com/taosir/wtcms/issues/1 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:wtcms_project:wtcms:1.0:*:*:*:*:*:*:*

Information

Published : 2018-04-21 18:29

Updated : 2018-05-25 07:33


NVD link : CVE-2018-10267

Mitre link : CVE-2018-10267


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

wtcms_project

  • wtcms