PT-2019-19254 · Wtcms · Wtcms

Assassins-White

·

Published

2019-02-18

·

Updated

2019-02-19

·

CVE-2019-8910

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WTCMS version 1.0
Description An issue was discovered that allows a CSRF attack through the "index.php?g=admin&m=setting&a=site post" endpoint, specifically targeting the site post action within the setting module of the admin interface.
Recommendations For WTCMS version 1.0, consider implementing CSRF protection measures, such as token-based validation, to prevent unauthorized requests to the "index.php?g=admin&m=setting&a=site post" endpoint. As a temporary workaround, restrict access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-8910

Affected Products

Wtcms