CSRF Vulnerability in UNL-CMS 7.59 Allows Unauthorized Website Settings Update

CSRF Vulnerability in UNL-CMS 7.59 Allows Unauthorized Website Settings Update

CVE-2018-17070 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay.

Learn more about our Web App Pen Testing.