VYPR

CWCMS

by CREDITWEST

CVEs (1)

  • CVE-2018-8972Mar 24, 2018
    risk 0.00cvss epss 0.00

    Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters.