PT-2018-11353 · Beescms · Beescms

Bay0Net

·

Published

2018-07-05

·

Updated

2018-08-27

·

CVE-2018-12739

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BEESCMS version 4.0
Description The issue allows for arbitrary addition of administrators due to a CSRF concern.
Recommendations For BEESCMS version 4.0, update to a version that includes a fix for this issue, as the current version allows for unauthorized modifications to administrator accounts.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12739

Affected Products

Beescms