First published: Tue Mar 27 2018(Updated: )
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-9092.
The title of this vulnerability is 'There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.'
The affected software is MiniCMS version 1.10.
The severity of CVE-2018-9092 is high (8.8).
To fix this vulnerability, update MiniCMS to a version that has addressed the CSRF vulnerability in mc-admin/conf.php (e.g., version 1.11 or higher).