CVE-2018-15564: CSRF
Published Aug 20, 2018
·Updated
An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.
Affected Software
1 affected component
Simple-cms Project Simple Cms<=2014-03-11
Event History
Aug 20, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-15564?
CVE-2018-15564 is classified as a high severity CSRF vulnerability.
2
What can an attacker do with CVE-2018-15564?
An attacker can delete any page from the Simple CMS by exploiting the CSRF vulnerability.
3
How do I fix CVE-2018-15564?
To fix CVE-2018-15564, update Simple CMS to a version released after March 11, 2014.
4
Which versions of Simple CMS are affected by CVE-2018-15564?
CVE-2018-15564 affects all versions of Simple CMS up to and including March 11, 2014.
5
Is there a patch available for CVE-2018-15564?
There is no specific patch, but upgrading to a later version of Simple CMS resolves CVE-2018-15564.