8.8
CVSSv3

CVE-2018-5969

Published: 24/01/2018 Updated: 12/02/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin account.

Vulnerable Product Search on Vulmon Subscribe to Product

photography cms project photography cms 1.0

Exploits

<!-- # # # # # # Exploit Title: Photography CMS 10 - Cross-Site Request Forgery (Add Admin) # Dork: N/A # Date: 23012018 # Vendor Homepage: ronnieswietekcom/ # Software Link: codecanyonnet/item/client-photo-studio-photography-cms/1191688 # Version: 10 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: CVE-2018-5 ...
Photography CMS version 10 suffers from a cross site request forgery vulnerability ...