CVE-2018-17366
High
|8.8Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to create a new administrator account on the MCMS platform, which could give them full control over the system. To exploit this, the attacker needs to trick a logged-in user into clicking a malicious link while they are using the application.
Technical Description
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged
Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$4,789($1K-$5K)
Vendor Response
Grade FPatched in 2706 days
Quick Information
Published
Sep 23, 2018
over 7 years ago
Last Modified
Feb 19, 2026
1 day ago
Vendor
mingsoft
Product
mcms