CSRF Vulnerability in RSVP Invitation Online 1.0 Allows Unauthorized Password Modification
CVE-2018-5976 · MEDIUM Severity
AV:N/AC:M/AU:N/C:P/I:P/A:P
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password.
Learn more about our Web Application Penetration Testing UK.