CVE-2018-9926: CSRF
Published Apr 10, 2018
·Updated
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Apr 10, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9926?
The severity of CVE-2018-9926 is high, with a CVSS score of 8.8.
2
How can I exploit CVE-2018-9926?
We do not condone or provide information on how to exploit vulnerabilities.
3
How do I fix CVE-2018-9926?
Upgrade to the latest version of WUZHI CMS (4.1.1) where this vulnerability has been patched.
4
Where can I find more information about CVE-2018-9926?
You can find more information about CVE-2018-9926 on the following references: [here](http://www.iwantacve.cn/index.php/archives/6/), [here](https://github.com/wuzhicms/wuzhicms/issues/128), and [here](https://www.exploit-db.com/exploits/44439/).