First published: Sat Jun 02 2018(Updated: )
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CmsEasy | =6.0-20180508 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11680 has a medium severity rating due to its potential impact on the application's integrity.
To fix CVE-2018-11680, update to the latest version of CmsEasy that addresses this CSRF vulnerability.
Yes, CVE-2018-11680 can be exploited for denial of service (DoS) attacks by abusing the IFRAME element.
The potential impacts of CVE-2018-11680 include unauthorized actions and resource depletion on the affected system.
CVE-2018-11680 specifically affects CmsEasy version 6.0-20180508 and earlier versions may also be vulnerable.