Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tinyfisher

#28816of 53,632
8.8Total CVSS
Vulnerabilities · 1
PT-2018-9738
8.8
2018-04-17
Tuzi · Tuzicms · CVE-2018-10185
Name of the Vulnerable Software and Affected Versions: TuziCMS version 2.0.6 Description: An issue in TuziCMS allows for a CSRF vulnerability, enabling the addition of an admin account. This is demonstrated through a history.pushState call. Recommendations: For TuziCMS version 2.0.6, update to a newer version that contains a fix for this issue, if available. As a temporary workaround, consider implementing CSRF protection measures to prevent unauthorized actions.