CVE-2018-16338: CSRF
Published Sep 2, 2018
·Updated
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
Affected Software
1 affected component
AuraCMS AuraCMS=2.3
Event History
Sep 2, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16338?
CVE-2018-16338 has a medium severity rating due to its potential impact on user credentials and administrative control.
2
How do I fix CVE-2018-16338?
To fix CVE-2018-16338, update to the latest version of AuraCMS that includes patches for the CSRF vulnerability.
3
Who is affected by CVE-2018-16338?
CVE-2018-16338 affects all installations of AuraCMS version 2.3.
4
What type of vulnerability is CVE-2018-16338?
CVE-2018-16338 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What can an attacker do with CVE-2018-16338?
An attacker could exploit CVE-2018-16338 to change the administrator's password and potentially gain unauthorized access to the system.