CVE-2018-8814
MEDIUMWolfCMS 0.8.3.1 - Cross-Site Request Forgery in Plugin Settings
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8814. PoCs published by Sureshbabu Narvaneni.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in WolfCMS 0.8.3.1, allowing attackers to modify plugin settings or uninstall plugins by tricking authenticated users into submitting malicious requests.
Description
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in WolfCMS 0.8.3.1, allowing attackers to modify plugin settings or uninstall plugins by tricking authenticated users into submitting malicious requests.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N