A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
References
Link Resource
http://packetstormsecurity.com/files/148268/LFCMS-3.7.0-Cross-Site-Request-Forgery.html Exploit Third Party Advisory VDB Entry
http://www.iwantacve.cn/index.php/archives/43/ Exploit Third Party Advisory
https://www.cnblogs.com/v1vvwv/p/9203740.html Exploit Third Party Advisory
https://www.exploit-db.com/exploits/44918/ Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-06-25T15:00:00

Updated: 2018-07-06T14:57:01

Reserved: 2018-06-20T00:00:00


Link: CVE-2018-12602

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-25T15:29:00.490

Modified: 2018-08-27T17:36:25.850


Link: CVE-2018-12602

JSON object: View

cve-icon Redhat Information

No data.

CWE