CVE-2018-20015: CSRF
Published Dec 10, 2018
·Updated
YzmCMS v5.2 has admin/role/add.html CSRF.
Affected Software
1 affected component
YzmCMS YzmCMS=5.2
Event History
Dec 10, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20015?
CVE-2018-20015 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-20015?
To fix CVE-2018-20015, apply the latest security patches and implement anti-CSRF tokens in the affected admin endpoints.
3
What type of vulnerability is CVE-2018-20015?
CVE-2018-20015 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which version of Yzmcms is affected by CVE-2018-20015?
CVE-2018-20015 affects Yzmcms version 5.2.
5
Can CVE-2018-20015 lead to unauthorized actions?
Yes, CVE-2018-20015 can allow attackers to execute unauthorized actions on behalf of the admin user.