CVE-2018-18712: CSRF
Published Oct 27, 2018
·Updated
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Oct 27, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Oct 29, 2018
Data Sourced
via NVD·12:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue in WUZHI CMS 4.1.0?
The vulnerability ID for this issue in WUZHI CMS 4.1.0 is CVE-2018-18712.
2
What is the severity of CVE-2018-18712?
The severity of CVE-2018-18712 is high with a CVSS score of 8.8.
3
How does CVE-2018-18712 affect WUZHI CMS 4.1.0?
CVE-2018-18712 allows an attacker to change the super administrator's username in WUZHI CMS 4.1.0 through a CSRF vulnerability.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-18712?
The CWE ID for CVE-2018-18712 is CWE-352.
5
Is there a fix available for CVE-2018-18712?
There is currently no information available about a fix for CVE-2018-18712. It is recommended to follow the official WUZHI CMS documentation for updates and patches.