CVE-2018-8972
24.03.2018, 22:29
Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters.
Vendor | Product | Version |
---|---|---|
creditwestbank | cwcms | 𝑥 < 2017-07-28 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration