CVE-2018-6888

HIGH

Typesetter - CSRF

Title source: rule

Description

An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.

Exploits (1)

exploitdb WORKING POC
by Navina Asrani · htmlwebappsphp
https://www.exploit-db.com/exploits/44029

Scores

CVSS v3 8.0
EPSS 0.0013
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
typesettercms/typesetter 5.1
Published Feb 12, 2018
Tracked Since Feb 18, 2026