CVE-2018-17366

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to create a new administrator account on the MCMS platform, which could give them full control over the system. To exploit this, the attacker needs to trick a logged-in user into clicking a malicious link while they are using the application.

Technical Description

An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$4,789($1K-$5K)
Vendor Response
Grade FPatched in 2706 days

Quick Information

Published

Sep 23, 2018

over 7 years ago

Last Modified

Feb 19, 2026

1 day ago

Vendor

mingsoft

Product

mcms