First published: Mon Feb 19 2018(Updated: )
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
5none Nonecms | =1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-7219.
The severity of CVE-2018-7219 is high with a severity value of 8.8.
CVE-2018-7219 affects NoneCms 1.3.0 by allowing CSRF attacks, which can be used to change admin passwords or add unauthorized accounts.
To fix CVE-2018-7219, it is recommended to update NoneCms to a version that has addressed the CSRF vulnerability.
More information about CVE-2018-7219 can be found at the following link: http://foreversong.cn/archives/1081