CSRF Vulnerability in EmpireCMS 7.5 Allows Unauthorized User Account Addition

CSRF Vulnerability in EmpireCMS 7.5 Allows Unauthorized User Account Addition

CVE-2018-18449 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.

Learn more about our Cms Pen Testing.