ZeroHour

CVE-2018-1000137

PoC
CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
Description

I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed without the administrator's knowledge.

Vendors
scilico
Products
i\, librarian
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.