First published: Sat Apr 20 2019(Updated: )
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ditcms | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11374 has a medium severity rating due to its potential for creating unauthorized admin user accounts.
CVE-2019-11374 allows an attacker to exploit a CSRF vulnerability to create a new admin user, compromising the integrity of the system.
To fix CVE-2019-11374, implement CSRF protection measures in your application, such as using tokens for sensitive actions.
CVE-2019-11374 specifically affects 74CMS version 5.0.1.
Yes, there are known exploits available that demonstrate the CSRF vulnerability in CVE-2019-11374.