First published: Mon Aug 06 2018(Updated: )
zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | =8.3. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14963 has been classified as a high severity vulnerability due to its potential for unauthorized actions via CSRF.
To fix CVE-2018-14963, implement CSRF tokens in the admin area to prevent unauthorized requests.
CVE-2018-14963 allows attackers to exploit CSRF vulnerabilities to perform unauthorized actions in zzcms 8.3.
If you are using zzcms version 8.3, then your installation is vulnerable to CVE-2018-14963.
CSRF, or Cross-Site Request Forgery, relates to CVE-2018-14963 as it exploits the lack of verification of user requests in zzcms.