CVE-2018-18711: CSRF
Published Oct 27, 2018
·Updated
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=editinfo.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Oct 27, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Oct 29, 2018
Data Sourced
via NVD·12:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-18711.
2
What is the severity of CVE-2018-18711?
The severity of CVE-2018-18711 is high with a score of 8.8.
3
How does the CSRF vulnerability in WUZHI CMS 4.1.0 work?
The CSRF vulnerability in WUZHI CMS 4.1.0 can allow an attacker to change the super administrator's password by sending a specially crafted request.
4
What is the affected software version?
The affected software version is WUZHI CMS 4.1.0.
5
Is there a fix available for this vulnerability?
Yes, a fix for this vulnerability may be available by upgrading to a newer version of WUZHI CMS.