CVE-2018-16339: CSRF
Published Sep 2, 2018
·Updated
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
Affected Software
1 affected component
Phome Empirecms=7.0
Event History
Sep 2, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16339?
CVE-2018-16339 is classified as a moderate severity vulnerability due to its potential to allow unauthorized access to the administrative interface.
2
How do I fix CVE-2018-16339?
To fix CVE-2018-16339, it is recommended to apply security patches provided by the vendor or implement CSRF tokens in the user management forms.
3
What type of vulnerability is CVE-2018-16339?
CVE-2018-16339 is a Cross-Site Request Forgery (CSRF) vulnerability affecting EmpireCMS 7.0.
4
Who is affected by CVE-2018-16339?
Users of EmpireCMS version 7.0 are affected by CVE-2018-16339 due to its CSRF nature.
5
What can an attacker do with CVE-2018-16339?
An attacker can exploit CVE-2018-16339 to add unauthorized administrators to the EmpireCMS system.