RSS   Vulnerabilities for 'Srcms'   RSS

2018-11-16
 
CVE-2018-19319

CWE-352
 

 
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.

 
 
CVE-2018-19318

CWE-352
 

 
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.

 
2018-07-15
 
CVE-2018-14069

CWE-352
 

 
An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add.

 
 
CVE-2018-14068

CWE-352
 

 
An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add.

 


Copyright 2024, cxsecurity.com

 

Back to Top