6.8
CVSSv2

CVE-2018-9926

Published: 10/04/2018 Updated: 27/02/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.

Vulnerable Product Search on Vulmon Subscribe to Product

wuzhicms wuzhicms 4.1.0

Exploits

# Exploit Title: WUZHI CMS 410 CSRF vulnerability add admin account # Date: 2018-04-10 # Exploit Author: taoge # Vendor Homepage: githubcom/wuzhicms/wuzhicms # Software Link: githubcom/wuzhicms/wuzhicms # Version: 410 # CVE : CVE-2018-9926 An issue was discovered in WUZHI CMS 410(githubcom/wuzhicms/wuzhicms/is ...
Wuzhi CMS version 410 suffers from an add admin cross site request forgery vulnerability ...