Files
CVEs-PoC/2018/CVE-2018-8908.md
T
2024-06-18 02:51:15 +02:00

18 lines
826 B
Markdown

### [CVE-2018-8908](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8908)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.
### POC
#### Reference
- https://www.exploit-db.com/exploits/44383/
#### Github
No PoCs found on GitHub currently.