CVE-2018-11500: CSRF
Published May 26, 2018
·Updated
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.
Affected Software
1 affected component
PublicCMS publiccms=4.0.20180210
Event History
May 26, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-11500.
2
What is the severity of CVE-2018-11500?
The severity of CVE-2018-11500 is high with a CVSS score of 8.8.
3
What is the affected software version?
The affected software version is PublicCMS V4.0.20180210.
4
What is the description of CVE-2018-11500?
The description of CVE-2018-11500 is that there is a CSRF vulnerability in PublicCMS V4.0.20180210 that can add an admin account.
5
Is there a fix for CVE-2018-11500?
Yes, a fix is available for CVE-2018-11500. Please refer to the provided reference link for more information.