First published: Mon Nov 05 2018(Updated: )
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Popojicms Popojicms | =2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18935 is a vulnerability discovered in PopojiCMS v2.0.1 that allows CSRF attacks via the po-admin/route.php?mod=component&act=addnew URI.
CVE-2018-18935 affects PopojiCMS v2.0.1 by allowing an attacker to perform CSRF attacks through the po-admin/route.php?mod=component&act=addnew URI.
CVE-2018-18935 has a severity level of high, with a CVSS score of 8.8.
To fix CVE-2018-18935 in PopojiCMS v2.0.1, it is recommended to apply the official patch or update to a newer version of the software.
More information about CVE-2018-18935 can be found at the following reference: [GitHub - PopojiCMS](https://github.com/PopojiCMS/PopojiCMS/issues/14)