Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-6888. PoCs published by Navina Asrani.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in TypeSetter CMS 5.1, allowing an attacker to create a new admin user via a crafted HTML form without requiring any security tokens.
Description
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in TypeSetter CMS 5.1, allowing an attacker to create a new admin user via a crafted HTML form without requiring any security tokens.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H