vendor:
GreenCMS
by:
xichao
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: GreenCMS
Affected Version From: v2.3.0603
Affected Version To: v2.3.0603
Patch Exists: YES
Related CWE: CVE-2018-11671
CPE: a:greencms:greencms:2.3.0603
Other Scripts:
N/A
Platforms Tested: None
2018
GreenCMS v2.3.0603 CSRF vulnerability add admin
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle.
Mitigation:
The vendor has released a patch to address this vulnerability.