Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sfpskywood

#15366de 53,634
17.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2018-14589
8.8
2018-10-27
Wuzhi · Wuzhi Cms · CVE-2018-18711
**Name of the Vulnerable Software and Affected Versions** WUZHI CMS version 4.1.0 **Description** A CSRF issue allows changing the super administrator's password via the "index.php?m=core&f=panel&v=edit info" API endpoint. **Recommendations** For WUZHI CMS version 4.1.0, update to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-14590
8.8
2018-10-27
Wuzhi · Wuzhi Cms · CVE-2018-18712
**Name of the Vulnerable Software and Affected Versions** WUZHI CMS version 4.1.0 **Description** A CSRF issue allows changing the super administrator's username via the "index.php?m=member&f=index&v=edit&uid=1" endpoint, specifically targeting the `uid` variable set to `1`, which corresponds to the super administrator account. **Recommendations** For WUZHI CMS version 4.1.0, as a temporary workaround, consider restricting access to the "index.php?m=member&f=index&v=edit&uid=1" endpoint to prevent unauthorized changes to the super administrator's username. At the moment, there is no information about a newer version that contains a fix for this issue.