m3lon

2 exploits Active since Nov 2018
CVE-2018-19051 WRITEUP MEDIUM WRITEUP
MetInfo 6.1.3 - Cross-Site Scripting via abt_type Parameter
MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.
CVSS 6.1
CVE-2018-20188 WRITEUP HIGH WORKING POC
FUEL CMS 1.4.3 - Cross-Site Request Forgery via users/create/
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
CVSS 8.8