vendor:
WolfCMS
by:
Sureshbabu Narvaneni
6.5
CVSS
MEDIUM
Cross-site request forgery (CSRF)
352
CWE
Product Name: WolfCMS
Affected Version From: 0.8.3.1
Affected Version To: 0.8.3.1
Patch Exists: YES
Related CWE: CVE-2018-8814
CPE: wolfcms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win7 Enterprise x86/Kali Linux 4.12 i686
2018
WolfCMS 0.8.3.1 Cross Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in WolfCMS before 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings and can uninstall plugins by sending malicious request.
Mitigation:
Upgrade to latest release.