First published: Sun Sep 02 2018(Updated: )
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16366 refers to a vulnerability discovered in idreamsoft iCMS V7.0.10 which allows CSRF (Cross-Site Request Forgery) attacks through the 'admincp.php?app=user&do=save' endpoint.
CVE-2018-16366 has a severity rating of 8.8, which is considered high.
CVE-2018-16366 affects idreamsoft iCMS V7.0.10 and allows CSRF attacks, which can potentially lead to unauthorized actions being performed on behalf of the user.
At the moment, there is no known fix for CVE-2018-16366, so it is recommended to follow best security practices and mitigate the risk by implementing additional security measures.
More information about CVE-2018-16366 can be found at the following link: [https://github.com/idreamsoft/iCMS/issues/32](https://github.com/idreamsoft/iCMS/issues/32)