CVE-2018-18842: CSRF
Published Oct 30, 2018
·Updated
CSRF exists in zbusers/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5.2.1935\(zero\)
Event History
Oct 30, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this CSRF vulnerability?
The vulnerability ID for this CSRF vulnerability is CVE-2018-18842.
2
Where does the CSRF vulnerability exist in Z-BlogPHP?
The CSRF vulnerability exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero).
3
What is the severity of the CSRF vulnerability in Z-BlogPHP?
The severity of the CSRF vulnerability in Z-BlogPHP is high with a severity value of 8.8.
4
How can the CSRF vulnerability be exploited?
The CSRF vulnerability can be exploited by remote attackers to execute arbitrary PHP code.
5
Are there any references available for this CSRF vulnerability?
Yes, there are references available for this CSRF vulnerability: 1. https://github.com/zblogcn/zblogphp/files/2524853/CSRF.Vulnerability.exists.in.the.file.of.Z-BLOG.1.5.2.1935.docx 2. https://github.com/zblogcn/zblogphp/issues/201