First published: Sat Feb 23 2019(Updated: )
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =3.0 | |
=3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for S-CMS PHP v3.0 CSRF vulnerability is CVE-2019-9040.
CVE-2019-9040 has a severity rating of 'high' with a score of 8.8.
The CSRF vulnerability in S-CMS PHP v3.0 allows an attacker to add a new admin user by exploiting the admin/ajax.php?type=admin&action=add URI.
By exploiting the CSRF vulnerability in S-CMS PHP v3.0, an attacker can add a new admin user without proper authorization.
To fix the CSRF vulnerability in S-CMS PHP v3.0, update to a patched version of the software when available and apply any recommended security updates.