First published: Sat Sep 08 2018(Updated: )
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chshcms Cscms | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of CScms 4.1 is CVE-2018-16732.
The severity of CVE-2018-16732 is high with a score of 8.8.
CVE-2018-16732 allows CSRF attacks through the upload/plugins/sys/admin/Setting.php file in CScms 4.1.
To fix CVE-2018-16732, you should update CScms to a version that includes a patch for the vulnerability.
You can find more information about CVE-2018-16732 in the references provided: [link1](https://github.com/AvaterXXX/CScms/blob/master/CScms_csrf.md) and [link2](https://www.patec.cn/newsshow.php?cid=24&id=123).