First published: Wed Mar 27 2019(Updated: )
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to CVE-2019-9040.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for S-CMS PHP v1.0 CSRF vulnerability is CVE-2019-10237.
The severity score of CVE-2019-10237 is 8.8 (high).
The CSRF vulnerability in S-CMS PHP v1.0 allows an attacker to add a new admin user by exploiting the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI.
The related vulnerability to CVE-2019-10237 is CVE-2019-9040.
At the moment, there is no known fix for CVE-2019-10237. It is recommended to apply any patches or updates provided by the vendor.