First published: Mon Feb 18 2019(Updated: )
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | <=7.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8902 is a CSRF vulnerability in idreamsoft iCMS through 7.0.14 that allows attackers to delete users' articles via the public/api.php?app=user URI.
CVE-2019-8902 has a severity rating of 5.7, which is considered medium.
CVE-2019-8902 affects idreamsoft iCMS versions up to and including 7.0.14.
Yes, updating idreamsoft iCMS to a version beyond 7.0.14 will fix the CSRF vulnerability.
More information about CVE-2019-8902 can be found at the following reference link: https://github.com/idreamsoft/iCMS/issues/56