CVE-2018-10312: CSRF
index.php?m=member&v=pwreset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10312?
CVE-2018-10312 is a vulnerability in WUZHI CMS 4.1.0 that allows CSRF attacks to change the password of a common member.
How severe is CVE-2018-10312?
CVE-2018-10312 has a severity rating of 8.8, which is considered high.
How can I exploit CVE-2018-10312?
We do not provide guidance on exploiting vulnerabilities. It is important to follow ethical guidelines and not engage in illegal activities.
How can I fix CVE-2018-10312?
Update WUZHI CMS to version 4.1.1 or later, which includes a fix for the vulnerability. Additionally, consider implementing CSRF protection mechanisms in your application.
Where can I find more information about CVE-2018-10312?
You can find more information about CVE-2018-10312 in the linked references: [Github Issue](https://github.com/wuzhicms/wuzhicms/issues/132) and [Exploit-DB](https://www.exploit-db.com/exploits/44504/).