CSRF Vulnerability in DouCo DouPHP 1.5 Allows Unauthorized Addition of Administrator Account

CSRF Vulnerability in DouCo DouPHP 1.5 Allows Unauthorized Addition of Administrator Account

CVE-2018-20419 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.

Learn more about our Web Application Penetration Testing UK.