Wuzhi · Wuzhi Cms · CVE-2018-18712
**Name of the Vulnerable Software and Affected Versions**
WUZHI CMS version 4.1.0
**Description**
A CSRF issue allows changing the super administrator's username via the "index.php?m=member&f=index&v=edit&uid=1" endpoint, specifically targeting the `uid` variable set to `1`, which corresponds to the super administrator account.
**Recommendations**
For WUZHI CMS version 4.1.0, as a temporary workaround, consider restricting access to the "index.php?m=member&f=index&v=edit&uid=1" endpoint to prevent unauthorized changes to the super administrator's username. At the moment, there is no information about a newer version that contains a fix for this issue.