An issue exists in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincontroller.php allows remote malicious users to add administrator accounts via m=admin&c=admin&a=add.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sdcms sdcms 1.5 |