Cross-Site Request Forgery Flaw in WUZHI CMS
CVE-2018-18711

8.8HIGH

Key Information:

Vendor

Wuzhicms

Status
Vendor
CVE Published:
29 October 2018

What is CVE-2018-18711?

An identified security issue in WUZHI CMS version 4.1.0 allows attackers to exploit Cross-Site Request Forgery (CSRF). This vulnerability permits unauthorized changes to the super administrator's password through a specially crafted request to the panel's edit_info function. This flaw can have severe implications for the integrity and security of the affected applications, highlighting the necessity for robust protection mechanisms against CSRF attacks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.