Vulnerability Description
A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Feifeicms | Feifeicms | 4.1.190209 |
Related Weaknesses (CWE)
References
- https://github.com/GodEpic/Vulnerability-detection/blob/master/feifeicms/FeiFeiCExploitThird Party Advisory
- https://github.com/GodEpic/Vulnerability-detection/blob/master/feifeicms/pocExploit
- https://github.com/GodEpic/Vulnerability-detection/blob/master/feifeicms/FeiFeiCExploitThird Party Advisory
- https://github.com/GodEpic/Vulnerability-detection/blob/master/feifeicms/pocExploit
FAQ
What is CVE-2020-18418?
CVE-2020-18418 is a vulnerability with a CVSS score of 8.8 (HIGH). A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.
How severe is CVE-2020-18418?
CVE-2020-18418 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-18418?
Check the references section above for vendor advisories and patch information. Affected products include: Feifeicms Feifeicms.