An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/user/add_post.html.
References
Link Resource
https://github.com/SQYY/CVE/blob/master/YxtCMF_C Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:49

Updated: 2022-10-03T16:21:49

Reserved: 2022-10-03T00:00:00


Link: CVE-2018-7733

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-03-06T18:29:00.690

Modified: 2018-03-26T18:58:10.417


Link: CVE-2018-7733

JSON object: View

cve-icon Redhat Information

No data.

CWE