VYPR
High severity8.8NVD Advisory· Published May 12, 2018· Updated Jun 17, 2026

CVE-2018-11004

CVE-2018-11004

Description

An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincontroller.php allows remote attackers to add administrator accounts via m=admin&c=admin&a=add.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.