PT-2018-15476 · Uwa · Uwa

Published

2018-12-30

·

Updated

2019-01-16

·

CVE-2018-20612

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UWA version 2.3.11
Description The issue allows for a CSRF attack via the index.php?g=admin&c=admin&a=add admin do endpoint.
Recommendations For version 2.3.11, consider implementing CSRF protection measures, such as token-based validation, to prevent unauthorized requests to the add admin do action in the admin controller.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20612

Affected Products

Uwa