First published: Mon Sep 03 2018(Updated: )
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16416 is a Cross-site request forgery (CSRF) vulnerability in FUEL CMS 1.4 that allows remote attackers to change the administrator's password.
CVE-2018-16416 is classified as a high severity vulnerability with a severity score of 8.8 out of 10.
CVE-2018-16416 affects FUEL CMS version 1.4.
To fix CVE-2018-16416, it is recommended to upgrade FUEL CMS to a version that includes the security patch.
You can find more information about CVE-2018-16416 at the following references: [Reference 1](http://www.iwantcve.cn/index.php/archives/48/) and [Reference 2](https://github.com/daylightstudio/FUEL-CMS/issues/481).