CVE-2018-7219: CSRF
Published Feb 19, 2018
·Updated
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.
Affected Software
1 affected component
5none Nonecms=1.3.0
Event History
Feb 19, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2018-7219.
2
What is the severity of CVE-2018-7219?
The severity of CVE-2018-7219 is high with a severity value of 8.8.
3
How does CVE-2018-7219 affect NoneCms 1.3.0?
CVE-2018-7219 affects NoneCms 1.3.0 by allowing CSRF attacks, which can be used to change admin passwords or add unauthorized accounts.
4
How can I fix CVE-2018-7219?
To fix CVE-2018-7219, it is recommended to update NoneCms to a version that has addressed the CSRF vulnerability.
5
Where can I find more information about CVE-2018-7219?
More information about CVE-2018-7219 can be found at the following link: http://foreversong.cn/archives/1081