First published: Wed Aug 08 2018(Updated: )
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue in Gxlcms 2.0 is CVE-2018-15177.
The severity level of CVE-2018-15177 is high with a CVSS score of 8.8.
The affected software version of CVE-2018-15177 is Gxlcms 2.0.
This vulnerability allows a CSRF attack to add an administrator account in Gxlcms 2.0.
Yes, you can find more information about CVE-2018-15177 at the following references: 1. http://www.gxlcms.com/ 2. https://exchange.xforce.ibmcloud.com/vulnerabilities/148132 3. https://gitee.com/gxlcms/gxlcms_news_system_2/issues/ILVLP