Vulnerabilities
Vulnerable Software
Chshcms:  Security Vulnerabilities
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-09-08
Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-09-04
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.
CVSS Score
6.5
EPSS Score
0.001
Published
2018-09-02


Contact Us

Shodan ® - All rights reserved