ZeroHour

CVE-2018-6888

PoC ×2
CVSS 3.0
8.0 high
EPSS
2%p79
Published
()
Modified
Description

An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.

Vendors
typesettercms
Products
typesetter
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.