vendor:
74CMS
by:
ax8
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: 74CMS
Affected Version From: v5.0.1
Affected Version To: v5.0.1
Patch Exists: NO
Related CWE: CVE-2019-11374
CPE: 74cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. A proof of concept HTML file is provided which can be used to create a new administrator user.
Mitigation:
Implementing a CSRF token in the application can help prevent this type of attack.