PoC Index

CVE-2018-6888

HIGH 8.0EPSS 1.9%

An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.

CVSS v3.0
8.0 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
1.93% chance of exploitation in the next 30 days, 79th percentile
Published
2018-02-12
Updated
2024-08-05

ExploitDB entries (1)

References

Related