CVE-2018-19291
15.11.2018, 06:29
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
Vendor | Product | Version |
---|---|---|
dilicms | dilicms | 2.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration