First published: Fri Jul 20 2018(Updated: )
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Metinfo Metinfo | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14420 is a vulnerability in MetInfo 6.0.0 that allows a CSRF attack to add a user account via a doaddsave action to admin/index.php.
CVE-2018-14420 has a severity score of 8.8, which is classified as high.
The CSRF attack in CVE-2018-14420 allows an attacker to add a user account by exploiting the doaddsave action in the admin/index.php page.
Yes, to fix CVE-2018-14420, update MetInfo to a version that is not affected by this vulnerability.
Yes, you can find more information about CVE-2018-14420 at the following link: [GitHub - Metinfo - XSS](https://github.com/AvaterXXX/Metinfo---XSS/blob/master/CSRF)