Vulnerability Description
OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpcoo | Oecms | >= 4.3 |
Related Weaknesses (CWE)
References
- https://github.com/LiodAir/images/blob/master/csrf.mdExploitThird Party Advisory
- https://github.com/LiodAir/images/blob/master/csrf.mdExploitThird Party Advisory
FAQ
What is CVE-2019-1010112?
CVE-2019-1010112 is a vulnerability with a CVSS score of 8.8 (HIGH). OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vecto...
How severe is CVE-2019-1010112?
CVE-2019-1010112 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1010112?
Check the references section above for vendor advisories and patch information. Affected products include: Phpcoo Oecms.