CVE-2018-25186
EUVD-2018-2163906.03.2026, 13:16
Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credentials by submitting forged POST requests to the profile endpoint. Attackers can craft HTML forms targeting the /kim/profile endpoint with hidden fields containing malicious user data like passwords and email addresses to update administrator accounts without authentication.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tina4 | tina4_stack | 1.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration