First published: Sun Sep 02 2018(Updated: )
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16338 has a medium severity rating due to its potential impact on user credentials and administrative control.
To fix CVE-2018-16338, update to the latest version of AuraCMS that includes patches for the CSRF vulnerability.
CVE-2018-16338 affects all installations of AuraCMS version 2.3.
CVE-2018-16338 is a Cross-Site Request Forgery (CSRF) vulnerability.
An attacker could exploit CVE-2018-16338 to change the administrator's password and potentially gain unauthorized access to the system.