PT-2018-18857 · Quickapps · Quickappscms

Fvi-Atto

·

Published

2018-03-28

·

Updated

2022-05-14

·

CVE-2018-9108

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QuickAppsCMS version 2.0.0-beta2
Description The issue allows an unauthorized remote attacker to create an account with admin privileges due to a CSRF vulnerability in the /admin/user/manage/add API endpoint.
Recommendations For QuickAppsCMS version 2.0.0-beta2, as a temporary workaround, consider disabling access to the /admin/user/manage/add endpoint until a patch is available. Restrict access to the admin user management functionality to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9108
GHSA-62G2-8P9F-GHJP

Affected Products

Quickappscms