CVE-2018-18742: CSRF
Published Oct 28, 2018
·Updated
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMSUser.php?Class=add&CF=user URI.
Affected Software
1 affected component
Sem-cms Semcms=3.4
Event History
Oct 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18742?
The severity of CVE-2018-18742 is high with a CVSS score of 8.8.
2
How does the CSRF issue in SEMCMS 3.4 occur?
The CSRF issue in SEMCMS 3.4 occurs via the admin/SEMCMS_User.php?Class=add&CF=user URI.
3
What software versions are affected by CVE-2018-18742?
SEMCMS version 3.4 is affected by CVE-2018-18742.
4
How can I fix the CSRF issue in SEMCMS 3.4?
To fix the CSRF issue in SEMCMS 3.4, update to a version that has a patch for this vulnerability or apply the recommended security measures provided by the vendor.
5
Where can I find more information about the CSRF issue in SEMCMS 3.4?
More information about the CSRF issue in SEMCMS 3.4 can be found at the following link: [https://github.com/AvaterXXX/SEMCMS/blob/master/CSRF.md](https://github.com/AvaterXXX/SEMCMS/blob/master/CSRF.md)