An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-09-16T21:00:00
Updated: 2024-08-05T10:39:59.561Z
Reserved: 2018-09-16T00:00:00
Link: CVE-2018-17104
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-09-16T21:29:02.173
Modified: 2024-11-21T03:53:53.347
Link: CVE-2018-17104
Redhat
No data.