8.8
CVSSv3

CVE-2018-15845

Published: 25/08/2018 Updated: 17/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gleezcms gleez cms 1.2.0

Exploits

# Exploit Title: Gleez CMS 120 - Cross-Site Request Forgery (Add Admin) # Date: 2018-08-24 # Exploit Author: GunEggWang # Vendor Homepage: gleezcmsorg/ # Software Link: githubcom/gleez/cms # Version: 120 # CVE : CVE-2018-15845 # Description: # There is a CSRF vulnerability that can add an administrator account in # Gleez CM ...
Gleez CMS version 120 suffers from a cross site request forgery vulnerability ...