6.8
CVSSv2

CVE-2018-14029

Published: 13/07/2018 Updated: 06/09/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an malicious user to take over a user account, as demonstrated by modifying the account's email field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

creatiwity witycms 0.6.2

Exploits

<!-- # Exploit Title: WityCMS 062 - Cross-Site Request Forgery (Password Change) # Vendor Homepage: creatiwitynet/witycms # Software Link: githubcom/Creatiwity/wityCMS/releases/tag/062 # Exploit Author: Porhai Eung # Website: wwwchhaipovcom # CVE: CVE-2018-14029 # Category: webapps 1 Description CSRF vulnerabil ...
WityCMS version 062 suffers from a cross site request forgery vulnerability ...