Vulnerability Details CVE-2018-19291
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.0%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 5.8
Products affected by CVE-2018-19291
-
cpe:2.3:a:dilicms:dilicms:2.4.0