8.8
CVSSv3

CVE-2018-11670

Published: 01/06/2018 Updated: 29/06/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows malicious users to execute arbitrary PHP code via the content parameter to index.php?m=admin&c=media&a=fileconnect.

Vulnerable Product Search on Vulmon Subscribe to Product

njtech greencms 2.3.0603

Exploits

# Exploit Title: GreenCMS v230603 CSRF vulnerability get webshell # Date: 2018-06-02 # Exploit Author: xichao # Vendor Homepage: githubcom/GreenCMS/GreenCMS # Software Link: githubcom/GreenCMS/GreenCMS # Version: v230603 # CVE : CVE-2018-11670 An issue was discovered in GreenCMS v230603 There is a CSRF vulnerability that ...
GreenCMS version 230603 suffers from multiple cross site request forgery vulnerabilities ...