CVE-2018-8893: CSRF
Published Mar 31, 2018
·Updated
Z-BlogPHP 1.5.1 Zero has CSRF in pluginedit.php, resulting in the ability to execute arbitrary PHP code.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5.1
Event History
Mar 31, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Z-BlogPHP?
The vulnerability ID for Z-BlogPHP is CVE-2018-8893.
2
What is the severity of CVE-2018-8893?
CVE-2018-8893 has a severity value of 8.8, which is considered high.
3
What is the affected version of Z-BlogPHP?
Z-BlogPHP version 1.5.1 is affected by CVE-2018-8893.
4
What is the impact of CVE-2018-8893?
CVE-2018-8893 allows attackers to execute arbitrary PHP code.
5
How can I fix CVE-2018-8893?
To fix CVE-2018-8893, update Z-BlogPHP to a version that is not affected by the vulnerability.