PT-2019-19254 · Wtcms · Wtcms
Assassins-White
·
Published
2019-02-18
·
Updated
2019-02-19
·
CVE-2019-8910
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WTCMS version 1.0
Description
An issue was discovered that allows a CSRF attack through the "index.php?g=admin&m=setting&a=site post" endpoint, specifically targeting the
site post action within the setting module of the admin interface.Recommendations
For WTCMS version 1.0, consider implementing CSRF protection measures, such as token-based validation, to prevent unauthorized requests to the "index.php?g=admin&m=setting&a=site post" endpoint. As a temporary workaround, restrict access to this endpoint to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wtcms