PT-2018-13520 · Idreamsoft · Icms

Published

2018-09-02

·

Updated

2019-04-16

·

CVE-2018-16365

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions idreamsoft iCMS version 7.0.10
Description An issue was discovered that allows Cross-Site Request Forgery (CSRF) attacks. The "admincp.php?app=group&do=save" endpoint is vulnerable to this issue.
Recommendations For idreamsoft iCMS version 7.0.10, consider implementing CSRF protection mechanisms, such as tokens, to prevent exploitation of the admincp.php?app=group&do=save endpoint. As a temporary workaround, restrict access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16365

Affected Products

Icms