ax8

2 exploits Active since Apr 2019
CVE-2019-11375 EXPLOITDB MEDIUM html WORKING POC
Msvod v10 - Cross-Site Request Forgery via admin/member/edit.html
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
CVSS 6.5
CVE-2019-11374 EXPLOITDB HIGH html WORKING POC
74cms 5.0.1 - Cross-Site Request Forgery via Admin User Addition
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
CVSS 8.8