vendor:
WUZHI CMS
by:
jiguang (s1@jiguang.in)
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: WUZHI CMS
Affected Version From: 4.1.0
Affected Version To: 4.1.0
Patch Exists: YES
Related CWE: CVE-2018-10312
CPE: a:wuzhicms:wuzhicms:4.1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
WUZHI CMS 4.1.0 – Cross-Site Request Forgery
An issue was discovered in WUZHI CMS 4.1.0 (https://github.com/wuzhicms/wuzhicms/issues/132) There is a csrf vulnerability that can modifying the member's password. via index.php?m=member&v=pw_reset After the member logged in. open the exp page
Mitigation:
The user should be aware of the risks of Cross-Site Request Forgery and take steps to protect against it, such as using a secure token or other authentication mechanism.