lunar cms vulnerabilities and exploits

6.8
CVSSv2
CVE-2014-4718

Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a request to admin/user_create.php or conduct cross-site scripting (XSS) attacks...

LunarcmsLunar Cms