CVE-2018-10248: CSRF
Published Apr 20, 2018
·Updated
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycledelete.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Apr 20, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-10248?
The severity of CVE-2018-10248 is medium with a severity value of 6.5.
2
What is the affected software of CVE-2018-10248?
The affected software of CVE-2018-10248 is WUZHI CMS version 4.1.0.
3
How does the CSRF vulnerability in CVE-2018-10248 work?
The CSRF vulnerability in CVE-2018-10248 allows an attacker to delete any article via a specific URL.
4
Is there a fix for CVE-2018-10248?
A fix for CVE-2018-10248 is not provided in the information available.
5
Where can I find more information about CVE-2018-10248?
More information about CVE-2018-10248 can be found at the following link: https://github.com/wuzhicms/wuzhicms/issues/130.