8
CVSSv3

CVE-2018-6888

Published: 12/02/2018 Updated: 06/03/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.

Vulnerable Product Search on Vulmon Subscribe to Product

typesettercms typesetter 5.1

Exploits

# Exploit Title: TypeSetter CMS 51 Cross Site Request Forgery # Date: 10-02-2018 # Exploit Author: Navina Asrani # Contact: twittercom/NavinaSanjay # Website: securitywarrior9blogspotin/ # Vendor Homepage: wwwtypesettercmscom/ # Version: 51 # CVE : NA # Category: Webapp CMS 1 Description The application allows malc ...