vendor:
WampServer
by:
Vipin Chaudhary
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: WampServer
Affected Version From: 3.1.2
Affected Version To: 3.1.2
Patch Exists: YES
Related CWE: CVE-2018-8817
CPE: a:wampserver:wampserver:3.1.2
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
WampServer 3.1.2 CSRF to add or delete any virtual hostsremotely
CSRF (Cross site request forgery) in WampServer 3.1.2 which allows a remote attacker to force any victim to add or delete virtual hosts.
Mitigation:
Update to version 3.1.3