CVE-2018-17103: CSRF
Published Sep 16, 2018
·Updated
DISPUTED An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter.
Affected Software
1 affected component
Get-simple Getsimple Cms=3.3.13
Event History
Sep 16, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Disputed
09:29 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-17103.
2
What is the severity level of CVE-2018-17103?
CVE-2018-17103 has a severity level of 8.8 (high).
3
What is the affected software of CVE-2018-17103?
The affected software of CVE-2018-17103 is GetSimple CMS version 3.3.13.
4
What is the impact of the vulnerability in GetSimple CMS?
The vulnerability allows an attacker to change the administrator's password.
5
Is there a fix available for CVE-2018-17103?
The vendor has not provided a fix for CVE-2018-17103. Please contact the vendor for further information.