CVE-2018-8908
HIGHFrog CMS 0.9.5 - Cross-Site Request Forgery in User Addition
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8908. PoCs published by Samrat Das.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Frog CMS 0.9.5, allowing an attacker to create a privileged admin user via a crafted HTML form. The PoC includes a form that submits a POST request to the user creation endpoint without requiring an anti-CSRF token.
Description
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Frog CMS 0.9.5, allowing an attacker to create a privileged admin user via a crafted HTML form. The PoC includes a form that submits a POST request to the user creation endpoint without requiring an anti-CSRF token.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H