PT-2026-24135 · Unknown · Instantcms

0Xhamy

·

Publicado

2026-03-09

·

Atualizado

2026-03-13

·

CVE-2026-28281

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions InstantCMS versions prior to 2.18.1
Description InstantCMS does not properly validate Cross-Site Request Forgery (CSRF) tokens. This allows attackers to perform actions on behalf of a user without their knowledge. Specifically, an attacker could grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests.
Recommendations Update to InstantCMS version 2.18.1 or later.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28281
GHSA-PP43-262Q-H73M

Produtos afetados

Instantcms