First published: Wed Mar 06 2019(Updated: )
MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9603 is a vulnerability in MiniCMS 1.10 that allows CSRF attacks to delete articles.
CVE-2019-9603 has a severity value of 6.5, which is considered medium.
CVE-2019-9603 allows attackers to perform CSRF attacks to delete articles in MiniCMS 1.10.
No, CVE-2019-9603 is a separate vulnerability from CVE-2018-18891.
At the moment, there is no known fix for CVE-2019-9603. It is recommended to update to a newer version of MiniCMS if available or consider implementing additional security measures to mitigate the risk.