First published: Sat May 26 2018(Updated: )
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sanluan PublicCMS | =4.0.20180210 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-11500.
The severity of CVE-2018-11500 is high with a CVSS score of 8.8.
The affected software version is PublicCMS V4.0.20180210.
The description of CVE-2018-11500 is that there is a CSRF vulnerability in PublicCMS V4.0.20180210 that can add an admin account.
Yes, a fix is available for CVE-2018-11500. Please refer to the provided reference link for more information.