CVE-2018-17366: CSRF
Published Sep 23, 2018
·Updated
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
Affected Software
3 affected components
maven/net.mingsoft:ms-mcms<=4.6.5
Mcms Project Mcms=4.6.5
Mingsoft MCMS=4.6.5
Event History
Sep 23, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
02:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-17366?
The severity of CVE-2018-17366 is high with a score of 8.8.
2
How does CVE-2018-17366 affect MCMS?
CVE-2018-17366 introduces a CSRF vulnerability that allows unauthorized users to create an administrator account.
3
What systems are impacted by CVE-2018-17366?
CVE-2018-17366 impacts MCMS version 4.6.5 and can affect any instance using that version.
4
How can I mitigate CVE-2018-17366?
To mitigate CVE-2018-17366, it is recommended to update to a patched version of the MCMS software.
5
What kind of attack is associated with CVE-2018-17366?
CVE-2018-17366 is associated with Cross-Site Request Forgery (CSRF) attacks.