8.8
CWE
352
Advisory Published
Updated

CVE-2018-1000092: CSRF

First published: Tue Mar 13 2018(Updated: )

CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page. This vulnerability appears to have been fixed in 2.2.6.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Simple CMS=2.2.5

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2018-1000092?

    CVE-2018-1000092 is considered a moderate severity vulnerability due to its potential for exploitation via CSRF in the Admin profile page.

  • How do I fix CVE-2018-1000092?

    To mitigate CVE-2018-1000092, upgrade CMS Made Simple to a version higher than 2.2.5 that addresses this CSRF vulnerability.

  • What is a Cross-Site Request Forgery (CSRF) vulnerability in CVE-2018-1000092?

    CVE-2018-1000092 exploits the CSRF vulnerability allowing unauthorized actions to be performed on behalf of logged-in users in CMS Made Simple.

  • In which versions of CMS Made Simple is CVE-2018-1000092 found?

    CVE-2018-1000092 is found specifically in CMS Made Simple version 2.2.5.

  • Can CVE-2018-1000092 be exploited remotely?

    Yes, CVE-2018-1000092 can be exploited remotely via a specially crafted web page targeting users with active sessions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203