CVE-2018-20188: CSRF
Published Dec 17, 2018
·Updated
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.4.3
Event History
Dec 17, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20188?
CVE-2018-20188 refers to a vulnerability in FUEL CMS 1.4.3 that allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks to add an administrator account.
2
How severe is CVE-2018-20188?
CVE-2018-20188 has a severity rating of 8.8, which is considered high.
3
How does CVE-2018-20188 affect FUEL CMS?
CVE-2018-20188 affects FUEL CMS 1.4.3, allowing an attacker to perform CSRF attacks via the users/create/ endpoint.
4
How can I fix CVE-2018-20188?
To fix CVE-2018-20188, it is recommended to update FUEL CMS to a version that includes a patch for this vulnerability.
5
Is there any additional information about CVE-2018-20188?
You can find additional information about CVE-2018-20188 in the provided reference link: https://github.com/m3lon/CVE/blob/master/CSRF/FUELCMS%20CSRF.md