CVE-2018-6656: CSRF
Published Feb 6, 2018
·Updated
Z-BlogPHP 1.5.1 has CSRF via zbusers/plugin/AppCentre/appdel.php, as demonstrated by deleting files and directories.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5.1
Remediation
Event History
Feb 6, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Z-BlogPHP 1.5.1 CSRF?
The vulnerability ID for Z-BlogPHP 1.5.1 CSRF is CVE-2018-6656.
2
What is the severity of CVE-2018-6656?
The severity of CVE-2018-6656 is medium with a CVSS score of 6.5.
3
How does the CSRF vulnerability in Z-BlogPHP 1.5.1 work?
The CSRF vulnerability in Z-BlogPHP 1.5.1 works by allowing an attacker to perform unauthorized actions on behalf of the victim user.
4
What is the affected software for CVE-2018-6656?
The affected software for CVE-2018-6656 is Z-BlogPHP version 1.5.1.
5
Is there a fix available for the Z-BlogPHP 1.5.1 CSRF vulnerability?
Yes, a fix is available for the Z-BlogPHP 1.5.1 CSRF vulnerability. Please refer to the provided references for more information.