Cross-Site Request Forgery in WUZHI CMS 4.1.0 by WUZHI
CVE-2018-10312
Key Information:
Badges
What is CVE-2018-10312?
In WUZHI CMS version 4.1.0, a Cross-Site Request Forgery (CSRF) vulnerability exists in the index.php file specifically at the 'm=member&v=pw_reset' parameter. This flaw allows an unauthorized attacker to send a specially crafted request that could change the password of any common member without their knowledge or consent. As a result, this can lead to unauthorized access and potential compromise of user accounts. It is crucial for users and administrators to ensure they apply proper security measures and updates to mitigate the risks associated with this vulnerability.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.