CVE-2018-11018: CSRF
Published May 13, 2018
·Updated
An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.
Affected Software
1 affected component
Pbootcms Pbootcms=1.0.7
Event History
May 13, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-11018.
2
What is the severity of CVE-2018-11018?
The severity of CVE-2018-11018 is high.
3
What is the affected software version?
The affected software version is PbootCMS v1.0.7.
4
How does this vulnerability occur?
This vulnerability occurs due to a Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php.
5
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability to add administrator accounts via admin.php/role/add.html.