Lfcms
by Lfdycms
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12603 | Hig | 0.60 | 8.8 | 0.04 | Jun 25, 2018 | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114. | ||
| CVE-2018-12602 | Hig | 0.60 | 8.8 | 0.03 | Jun 25, 2018 | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. |
- risk 0.60cvss 8.8epss 0.04
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.
- risk 0.60cvss 8.8epss 0.03
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.