CVE-2018-9927: CSRF
Published Apr 10, 2018
·Updated
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Apr 10, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9927?
The severity of CVE-2018-9927 is rated as high with a CVSS score of 8.8.
2
What is the affected software version of CVE-2018-9927?
The affected software version of CVE-2018-9927 is WUZHI CMS 4.1.0.
3
How does the CSRF vulnerability in CVE-2018-9927 work?
The CSRF vulnerability in CVE-2018-9927 allows an attacker to add a user account through the index.php?m=member&f=index&v=add URL.
4
Are there any known references for CVE-2018-9927?
Yes, there are references available for CVE-2018-9927. You can find them at http://www.iwantacve.cn/index.php/archives/7/ and https://github.com/wuzhicms/wuzhicms/issues/128.
5
What is the Common Weakness Enumeration (CWE) ID of CVE-2018-9927?
The Common Weakness Enumeration (CWE) ID of CVE-2018-9927 is CWE-352.