PT-2018-19091 · Idreamsoft · Icms

Publicado

2018-04-10

·

Atualizado

2018-04-17

·

CVE-2018-9923

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions idreamsoft iCMS versions prior to 7.0.8
Description An issue exists where CSRF is present in the admincp.php file. This can be demonstrated by adding an article via the "app=article&do=save&frame=iPHP" request to the "/admincp.php" endpoint, using variables such as app, do, and frame.
Recommendations For versions prior to 7.0.8, update to version 7.0.8 or later to resolve the issue.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-9923

Produtos afetados

Icms