8.8
CVSSv3

CVE-2018-10312

Published: 24/04/2018 Updated: 24/05/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.

Vulnerable Product Search on Vulmon Subscribe to Product

wuzhicms wuzhi cms 4.1.0

Exploits

# Exploit Title: WUZHI CMS 410 - Cross-Site Request Forgery # Date: 2018-04-23 # Exploit Author: jiguang (s1@jiguangin) # Vendor Homepage: githubcom/wuzhicms/wuzhicms # Software Link: githubcom/wuzhicms/wuzhicms # Version: 410 # CVE: CVE-2018-10312 An issue was discovered in WUZHI CMS 410 (githubcom/wuzhicms/wuzhi ...
Wuzhi CMS version 410 suffers from a cross site request forgery vulnerability ...