CVE-2018-10223: CSRF
Published Apr 19, 2018
·Updated
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/adminmanage/add.html.
Affected Software
1 affected component
YzmCMS YzmCMS=3.8
Event History
Apr 19, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10223?
CVE-2018-10223 is classified as a medium severity vulnerability due to its potential to allow unauthorized administrative access.
2
How do I fix CVE-2018-10223?
To fix CVE-2018-10223, update YzmCMS to a newer version that addresses the CSRF vulnerability.
3
What type of vulnerability is CVE-2018-10223?
CVE-2018-10223 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Can CVE-2018-10223 lead to unauthorized access?
Yes, CVE-2018-10223 can enable an attacker to create an admin account, leading to unauthorized access.
5
Which software version is affected by CVE-2018-10223?
CVE-2018-10223 specifically affects YzmCMS version 3.8.