High severity8.8NVD Advisory· Published Sep 5, 2018· Updated Jun 17, 2026
CVE-2018-15682
CVE-2018-15682
Description
An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending private messages to users by luring an authenticated user to a web page that automatically submits a form on their behalf.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:btiteam:xbtit:*:*:*:*:*:*:*:*range: <=2.5.4
Patches
Vulnerability mechanics
References
1- rastating.github.io/xbtit-multiple-vulnerabilities/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.