8.8
CVSSv3

CVE-2018-5976

Published: 24/01/2018 Updated: 12/02/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password.

Vulnerable Product Search on Vulmon Subscribe to Product

rsvp invitation online project rsvp invitation online 1.0

Exploits

<!-- # # # # # # Exploit Title: RSVP Invitation Online 10 - Cross-Site Request Forgery (Update Admin Pass) # Dork: N/A # Date: 23012018 # Vendor Homepage: putrazendratolink/ # Software Link: wwwcodegrapecom/item/rsvp-invitation-online/3890 # Demo: putrazendratolink/rsvp/loginphp # Version: 10 # Category: Webapps # ...
RSVP Invitation Online version 10 suffers from a cross site request forgery vulnerability ...