vendor:
WUZHI CMS
by:
taoge
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: WUZHI CMS
Affected Version From: 4.1.2000
Affected Version To: 4.1.2000
Patch Exists: NO
Related CWE: CVE-2018-9926
CPE: a:wuzhicms:wuzhicms:4.1.0
Platforms Tested:
2018
WUZHI CMS 4.1.0 CSRF vulnerability add admin account
There is a CSRF vulnerability in WUZHI CMS 4.1.0 that can add an admin account via index.php?m=core&f=power&v=add. After the administrator logs in, the exploit can be triggered by opening the CSRF exploit page.
Mitigation:
Apply the vendor's patch or upgrade to a fixed version of the software.